agora inbox for [email protected]help / color / mirror / Atom feed
[PATCH v37 04/11] Add Incremental View Maintenance support to pg_dump 496+ messages / 2 participants [nested] [flat]
* [PATCH v37 04/11] Add Incremental View Maintenance support to pg_dump @ 2020-11-11 08:01 Yugo Nagata <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Yugo Nagata @ 2020-11-11 08:01 UTC (permalink / raw) Support CREATE INCREMENTAL MATERIALIZED VIEW syntax. --- src/bin/pg_dump/pg_dump.c | 18 +++++++++++++++--- src/bin/pg_dump/pg_dump.h | 2 ++ src/bin/pg_dump/t/002_pg_dump.pl | 18 ++++++++++++++++++ 3 files changed, 35 insertions(+), 3 deletions(-) diff --git a/src/bin/pg_dump/pg_dump.c b/src/bin/pg_dump/pg_dump.c index d56dcc701ce..b1d37675f66 100644 --- a/src/bin/pg_dump/pg_dump.c +++ b/src/bin/pg_dump/pg_dump.c @@ -7323,6 +7323,7 @@ getTables(Archive *fout, int *numTables) int i_relacl; int i_acldefault; int i_ispartition; + int i_isivm; /* * Find all the tables and table-like objects. @@ -7432,10 +7433,17 @@ getTables(Archive *fout, int *numTables) if (fout->remoteVersion >= 100000) appendPQExpBufferStr(query, - "c.relispartition AS ispartition "); + "c.relispartition AS ispartition, "); else appendPQExpBufferStr(query, - "false AS ispartition "); + "false AS ispartition, "); + + if (fout->remoteVersion >= 180000) + appendPQExpBufferStr(query, + "c.relisivm AS isivm "); + else + appendPQExpBufferStr(query, + "false AS isivm "); /* * Left join to pg_depend to pick up dependency info linking sequences to @@ -7548,6 +7556,7 @@ getTables(Archive *fout, int *numTables) i_relacl = PQfnumber(res, "relacl"); i_acldefault = PQfnumber(res, "acldefault"); i_ispartition = PQfnumber(res, "ispartition"); + i_isivm = PQfnumber(res, "isivm"); if (dopt->lockWaitTimeout) { @@ -7630,6 +7639,7 @@ getTables(Archive *fout, int *numTables) tblinfo[i].amname = pg_strdup(PQgetvalue(res, i, i_amname)); tblinfo[i].is_identity_sequence = (strcmp(PQgetvalue(res, i, i_is_identity_sequence), "t") == 0); tblinfo[i].ispartition = (strcmp(PQgetvalue(res, i, i_ispartition), "t") == 0); + tblinfo[i].isivm = (strcmp(PQgetvalue(res, i, i_isivm), "t") == 0); /* other fields were zeroed above */ @@ -17452,10 +17462,12 @@ dumpTableSchema(Archive *fout, const TableInfo *tbinfo) * PostgreSQL 18 has disabled UNLOGGED for partitioned tables, so * ignore it when dumping if it was set in this case. */ - appendPQExpBuffer(q, "CREATE %s%s %s", + appendPQExpBuffer(q, "CREATE %s%s%s %s", (tbinfo->relpersistence == RELPERSISTENCE_UNLOGGED && tbinfo->relkind != RELKIND_PARTITIONED_TABLE) ? "UNLOGGED " : "", + tbinfo->relkind == RELKIND_MATVIEW && tbinfo->isivm ? + "INCREMENTAL " : "", reltypename, qualrelname); diff --git a/src/bin/pg_dump/pg_dump.h b/src/bin/pg_dump/pg_dump.h index 5a6726d8b12..4408c504323 100644 --- a/src/bin/pg_dump/pg_dump.h +++ b/src/bin/pg_dump/pg_dump.h @@ -347,6 +347,8 @@ typedef struct _tableInfo int numParents; /* number of (immediate) parent tables */ struct _tableInfo **parents; /* TableInfos of immediate parents */ + bool isivm; /* is incrementally maintainable materialized view? */ + /* * These fields are computed only if we decide the table is interesting * (it's either a table to dump, or a direct parent of a dumpable table). diff --git a/src/bin/pg_dump/t/002_pg_dump.pl b/src/bin/pg_dump/t/002_pg_dump.pl index 3ee9fda50e4..7c38d3023f0 100644 --- a/src/bin/pg_dump/t/002_pg_dump.pl +++ b/src/bin/pg_dump/t/002_pg_dump.pl @@ -2992,6 +2992,24 @@ my %tests = ( }, }, + 'CREATE MATERIALIZED VIEW matview_ivm' => { + create_order => 21, + create_sql => 'CREATE INCREMENTAL MATERIALIZED VIEW dump_test.matview_ivm (col1) AS + SELECT col1 FROM dump_test.test_table;', + regexp => qr/^ + \QCREATE INCREMENTAL MATERIALIZED VIEW dump_test.matview_ivm AS\E + \n\s+\QSELECT col1\E + \n\s+\QFROM dump_test.test_table\E + \n\s+\QWITH NO DATA;\E + /xm, + like => + { %full_runs, %dump_test_schema_runs, section_pre_data => 1, }, + unlike => { + exclude_dump_test_schema => 1, + only_dump_measurement => 1, + }, + }, + 'CREATE POLICY p1 ON test_table' => { create_order => 22, create_sql => 'CREATE POLICY p1 ON dump_test.test_table -- 2.43.0 --Multipart=_Fri__29_May_2026_23_14_17_+0900_Te0o73X2VqYK57Gd Content-Type: text/x-diff; name="v37-0003-Allow-to-prolong-life-span-of-transition-tables-.patch" Content-Disposition: attachment; filename="v37-0003-Allow-to-prolong-life-span-of-transition-tables-.patch" Content-Transfer-Encoding: 7bit ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
* [PATCH] Restructure repack worker teardown @ 2026-05-18 17:13 Álvaro Herrera <[email protected]> 0 siblings, 0 replies; 496+ messages in thread From: Álvaro Herrera @ 2026-05-18 17:13 UTC (permalink / raw) The original code would leave a shared memory segment unreleased if we fail partway through initialization. Change the shutdown order so that we already free it. Author: Álvaro Herrera <[email protected]> Discussion: https://postgr.es/m/[email protected] --- src/backend/commands/repack.c | 67 ++++++++++++++++------------------- 1 file changed, 31 insertions(+), 36 deletions(-) diff --git a/src/backend/commands/repack.c b/src/backend/commands/repack.c index bfc62c8f752..c9064d8fd13 100644 --- a/src/backend/commands/repack.c +++ b/src/backend/commands/repack.c @@ -3411,10 +3411,14 @@ start_repack_decoding_worker(Oid relid) shm_mq_handle *mqh; BackgroundWorker bgw; + decoding_worker = palloc0_object(DecodingWorker); + /* Setup shared memory. */ size = BUFFERALIGN(offsetof(DecodingWorkerShared, error_queue)) + BUFFERALIGN(REPACK_ERROR_QUEUE_SIZE); seg = dsm_create(size, 0); + decoding_worker->seg = seg; + shared = (DecodingWorkerShared *) dsm_segment_address(seg); shared->initialized = false; shared->lsn_upto = InvalidXLogRecPtr; @@ -3454,14 +3458,12 @@ start_repack_decoding_worker(Oid relid) bgw.bgw_main_arg = UInt32GetDatum(dsm_segment_handle(seg)); bgw.bgw_notify_pid = MyProcPid; - decoding_worker = palloc0_object(DecodingWorker); if (!RegisterDynamicBackgroundWorker(&bgw, &decoding_worker->handle)) ereport(ERROR, errcode(ERRCODE_CONFIGURATION_LIMIT_EXCEEDED), errmsg("out of background worker slots"), errhint("You might need to increase \"%s\".", "max_worker_processes")); - decoding_worker->seg = seg; decoding_worker->error_mqh = mqh; /* @@ -3487,17 +3489,6 @@ start_repack_decoding_worker(Oid relid) ConditionVariableCancelSleep(); } -/* - * PG_ENSURE_ERROR_CLEANUP callback to stop the decoding worker. - * This ensures the worker is terminated on both ERROR and FATAL exits, - * unlike PG_FINALLY which only handles ERROR. - */ -static void -repack_decoding_worker_cleanup_cb(int code, Datum arg) -{ - stop_repack_decoding_worker(); -} - /* * Stop the decoding worker and cleanup the related resources. * @@ -3508,39 +3499,43 @@ static void stop_repack_decoding_worker(void) { BgwHandleStatus status; + dsm_segment *dsmseg; - /* Haven't reached the worker startup? */ + /* Nothing to do if no worker was set up. */ if (decoding_worker == NULL) return; - /* Could not register the worker? */ - if (decoding_worker->handle == NULL) - return; + /* Terminate the worker process, if one is running. */ + if (decoding_worker->handle != NULL) + { + TerminateBackgroundWorker(decoding_worker->handle); + /* The worker should really exit before the REPACK command does. */ + HOLD_INTERRUPTS(); + status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); + RESUME_INTERRUPTS(); - TerminateBackgroundWorker(decoding_worker->handle); - /* The worker should really exit before the REPACK command does. */ - HOLD_INTERRUPTS(); - status = WaitForBackgroundWorkerShutdown(decoding_worker->handle); - RESUME_INTERRUPTS(); - - if (status == BGWH_POSTMASTER_DIED) - ereport(FATAL, - errcode(ERRCODE_ADMIN_SHUTDOWN), - errmsg("postmaster exited during REPACK command")); - - shm_mq_detach(decoding_worker->error_mqh); + if (status == BGWH_POSTMASTER_DIED) + ereport(FATAL, + errcode(ERRCODE_ADMIN_SHUTDOWN), + errmsg("postmaster exited during REPACK command")); + } /* - * If we could not cancel the current sleep due to ERROR, do that before - * we detach from the shared memory the condition variable is located in. - * If we did not, the bgworker ERROR handling code would try and fail - * badly. + * Now detach from our shared memory segment. In error cases there might + * still be messages from the worker in the queue, which ProcessInterrupts + * would try to read; this is pointless (and causes an assertion failure), + * so set the global pointer to NULL to have ProcessRepackMessages ignore + * them. */ - ConditionVariableCancelSleep(); - - dsm_detach(decoding_worker->seg); + dsmseg = decoding_worker->seg; pfree(decoding_worker); decoding_worker = NULL; + + /* We must also cancel the current sleep, if one is still set up */ + ConditionVariableCancelSleep(); + + if (dsmseg != NULL) + dsm_detach(dsmseg); } /* stop_repack_decoding_worker, wrapped as a before_shmem_exit callback */ -- 2.47.3 --b42ct6adeyjj4cbm-- ^ permalink raw reply [nested|flat] 496+ messages in thread
end of thread, other threads:[~2026-05-18 17:13 UTC | newest] Thread overview: 496+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2020-11-11 08:01 [PATCH v37 04/11] Add Incremental View Maintenance support to pg_dump Yugo Nagata <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]> 2026-05-18 17:13 [PATCH] Restructure repack worker teardown Álvaro Herrera <[email protected]>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox