agora inbox for [email protected]help / color / mirror / Atom feed
[PATCH v5 12/12] s/recommendable/recommended 486+ messages / 3 participants [nested] [flat]
* [PATCH v3 11/12] s/recommendable/recommended @ 2019-05-10 02:22 Justin Pryzby <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Justin Pryzby @ 2019-05-10 02:22 UTC (permalink / raw) --- doc/src/sgml/btree.sgml | 2 +- doc/src/sgml/libpq.sgml | 2 +- doc/src/sgml/runtime.sgml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/src/sgml/btree.sgml b/doc/src/sgml/btree.sgml index 996932e..283db7f 100644 --- a/doc/src/sgml/btree.sgml +++ b/doc/src/sgml/btree.sgml @@ -60,7 +60,7 @@ contain the single-type operators (and associated support functions) for its input data type, while cross-type comparison operators and support functions are <quote>loose</quote> in the family. It is - recommendable that a complete set of cross-type operators be included + recommended that a complete set of cross-type operators be included in the family, thus ensuring that the planner can represent any comparison conditions that it deduces from transitivity. </para> diff --git a/doc/src/sgml/libpq.sgml b/doc/src/sgml/libpq.sgml index 8a8427f..4b031ff 100644 --- a/doc/src/sgml/libpq.sgml +++ b/doc/src/sgml/libpq.sgml @@ -7107,7 +7107,7 @@ int PQresultSetInstanceData(PGresult *res, PGEventProc proc, void *data); Beware that any storage represented by <parameter>data</parameter> will not be accounted for by <function>PQresultMemorySize</function>, unless it is allocated using <function>PQresultAlloc</function>. - (Doing so is recommendable because it eliminates the need to free + (Doing so is recommended because it eliminates the need to free such storage explicitly when the result is destroyed.) </para> </listitem> diff --git a/doc/src/sgml/runtime.sgml b/doc/src/sgml/runtime.sgml index 798da30..21a7ce3 100644 --- a/doc/src/sgml/runtime.sgml +++ b/doc/src/sgml/runtime.sgml @@ -111,7 +111,7 @@ <command>initdb</command> will attempt to create the directory you specify if it does not already exist. Of course, this will fail if <command>initdb</command> does not have permissions to write in the - parent directory. It's generally recommendable that the + parent directory. It's generally recommended that the <productname>PostgreSQL</productname> user own not just the data directory but its parent directory as well, so that this should not be a problem. If the desired parent directory doesn't exist either, -- 2.7.4 --cWoXeonUoKmBZSoM Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="v3-0012-Cleanup-remove-update-references-to-OID-column.patch" ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH v5 12/12] s/recommendable/recommended @ 2019-05-10 02:22 Justin Pryzby <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Justin Pryzby @ 2019-05-10 02:22 UTC (permalink / raw) --- doc/src/sgml/btree.sgml | 2 +- doc/src/sgml/libpq.sgml | 2 +- doc/src/sgml/runtime.sgml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/src/sgml/btree.sgml b/doc/src/sgml/btree.sgml index 5881ea5..b0e0f08 100644 --- a/doc/src/sgml/btree.sgml +++ b/doc/src/sgml/btree.sgml @@ -60,7 +60,7 @@ contain the single-type operators (and associated support functions) for its input data type, while cross-type comparison operators and support functions are <quote>loose</quote> in the family. It is - recommendable that a complete set of cross-type operators be included + recommended that a complete set of cross-type operators be included in the family, thus ensuring that the planner can represent any comparison conditions that it deduces from transitivity. </para> diff --git a/doc/src/sgml/libpq.sgml b/doc/src/sgml/libpq.sgml index 8a8427f..4b031ff 100644 --- a/doc/src/sgml/libpq.sgml +++ b/doc/src/sgml/libpq.sgml @@ -7107,7 +7107,7 @@ int PQresultSetInstanceData(PGresult *res, PGEventProc proc, void *data); Beware that any storage represented by <parameter>data</parameter> will not be accounted for by <function>PQresultMemorySize</function>, unless it is allocated using <function>PQresultAlloc</function>. - (Doing so is recommendable because it eliminates the need to free + (Doing so is recommended because it eliminates the need to free such storage explicitly when the result is destroyed.) </para> </listitem> diff --git a/doc/src/sgml/runtime.sgml b/doc/src/sgml/runtime.sgml index ecdaafc..e3d0dec 100644 --- a/doc/src/sgml/runtime.sgml +++ b/doc/src/sgml/runtime.sgml @@ -111,7 +111,7 @@ <command>initdb</command> will attempt to create the directory you specify if it does not already exist. Of course, this will fail if <command>initdb</command> does not have permissions to write in the - parent directory. It's generally recommendable that the + parent directory. It's generally recommended that the <productname>PostgreSQL</productname> user own not just the data directory but its parent directory as well, so that this should not be a problem. If the desired parent directory doesn't exist either, -- 2.7.4 --FkmkrVfFsRoUs1wW-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH v24 2/8] Row pattern recognition patch (parse/analysis). @ 2024-12-19 06:06 Tatsuo Ishii <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Tatsuo Ishii @ 2024-12-19 06:06 UTC (permalink / raw) --- src/backend/parser/parse_agg.c | 7 + src/backend/parser/parse_clause.c | 297 +++++++++++++++++++++++++++++- src/backend/parser/parse_expr.c | 6 + src/backend/parser/parse_func.c | 3 + 4 files changed, 312 insertions(+), 1 deletion(-) diff --git a/src/backend/parser/parse_agg.c b/src/backend/parser/parse_agg.c index 04b4596a65..6af3bcb375 100644 --- a/src/backend/parser/parse_agg.c +++ b/src/backend/parser/parse_agg.c @@ -580,6 +580,10 @@ check_agglevels_and_constraints(ParseState *pstate, Node *expr) errkind = true; break; + case EXPR_KIND_RPR_DEFINE: + errkind = true; + break; + /* * There is intentionally no default: case here, so that the * compiler will warn if we add a new ParseExprKind without @@ -970,6 +974,9 @@ transformWindowFuncCall(ParseState *pstate, WindowFunc *wfunc, case EXPR_KIND_CYCLE_MARK: errkind = true; break; + case EXPR_KIND_RPR_DEFINE: + errkind = true; + break; /* * There is intentionally no default: case here, so that the diff --git a/src/backend/parser/parse_clause.c b/src/backend/parser/parse_clause.c index 979926b605..5a44c68b08 100644 --- a/src/backend/parser/parse_clause.c +++ b/src/backend/parser/parse_clause.c @@ -96,7 +96,14 @@ static WindowClause *findWindowClause(List *wclist, const char *name); static Node *transformFrameOffset(ParseState *pstate, int frameOptions, Oid rangeopfamily, Oid rangeopcintype, Oid *inRangeFunc, Node *clause); - +static void transformRPR(ParseState *pstate, WindowClause *wc, WindowDef *windef, + List **targetlist); +static List *transformDefineClause(ParseState *pstate, WindowClause *wc, WindowDef *windef, + List **targetlist); +static void transformPatternClause(ParseState *pstate, WindowClause *wc, + WindowDef *windef); +static List *transformMeasureClause(ParseState *pstate, WindowClause *wc, + WindowDef *windef); /* * transformFromClause - @@ -2954,6 +2961,10 @@ transformWindowDefinitions(ParseState *pstate, rangeopfamily, rangeopcintype, &wc->endInRangeFunc, windef->endOffset); + + /* Process Row Pattern Recognition related clauses */ + transformRPR(pstate, wc, windef, targetlist); + wc->winref = winref; result = lappend(result, wc); @@ -3821,3 +3832,287 @@ transformFrameOffset(ParseState *pstate, int frameOptions, return node; } + +/* + * transformRPR + * Process Row Pattern Recognition related clauses + */ +static void +transformRPR(ParseState *pstate, WindowClause *wc, WindowDef *windef, + List **targetlist) +{ + /* + * Window definition exists? + */ + if (windef == NULL) + return; + + /* + * Row Pattern Common Syntax clause exists? + */ + if (windef->rpCommonSyntax == NULL) + return; + + /* Check Frame option. Frame must start at current row */ + if ((wc->frameOptions & FRAMEOPTION_START_CURRENT_ROW) == 0) + ereport(ERROR, + (errcode(ERRCODE_SYNTAX_ERROR), + errmsg("FRAME must start at current row when row patttern recognition is used"))); + + /* Transform AFTER MACH SKIP TO clause */ + wc->rpSkipTo = windef->rpCommonSyntax->rpSkipTo; + + /* Transform AFTER MACH SKIP TO variable */ + wc->rpSkipVariable = windef->rpCommonSyntax->rpSkipVariable; + + /* Transform SEEK or INITIAL clause */ + wc->initial = windef->rpCommonSyntax->initial; + + /* Transform DEFINE clause into list of TargetEntry's */ + wc->defineClause = transformDefineClause(pstate, wc, windef, targetlist); + + /* Check PATTERN clause and copy to patternClause */ + transformPatternClause(pstate, wc, windef); + + /* Transform MEASURE clause */ + transformMeasureClause(pstate, wc, windef); +} + +/* + * transformDefineClause + * Process DEFINE clause and transform ResTarget into list of + * TargetEntry. + * + * XXX we only support column reference in row pattern definition search + * condition, e.g. "price". <row pattern definition variable name>.<column + * reference> is not supported, e.g. "A.price". + */ +static List * +transformDefineClause(ParseState *pstate, WindowClause *wc, WindowDef *windef, + List **targetlist) +{ + /* DEFINE variable name initials */ + static char *defineVariableInitials = "abcdefghijklmnopqrstuvwxyz"; + + ListCell *lc, + *l; + ResTarget *restarget, + *r; + List *restargets; + List *defineClause; + char *name; + int initialLen; + int i; + + /* + * If Row Definition Common Syntax exists, DEFINE clause must exist. (the + * raw parser should have already checked it.) + */ + Assert(windef->rpCommonSyntax->rpDefs != NULL); + + /* + * Check and add "A AS A IS TRUE" if pattern variable is missing in DEFINE + * per the SQL standard. + */ + restargets = NIL; + foreach(lc, windef->rpCommonSyntax->rpPatterns) + { + A_Expr *a; + bool found = false; + + if (!IsA(lfirst(lc), A_Expr)) + ereport(ERROR, + errmsg("node type is not A_Expr")); + + a = (A_Expr *) lfirst(lc); + name = strVal(a->lexpr); + + foreach(l, windef->rpCommonSyntax->rpDefs) + { + restarget = (ResTarget *) lfirst(l); + + if (!strcmp(restarget->name, name)) + { + found = true; + break; + } + } + + if (!found) + { + /* + * "name" is missing. So create "name AS name IS TRUE" ResTarget + * node and add it to the temporary list. + */ + A_Const *n; + + restarget = makeNode(ResTarget); + n = makeNode(A_Const); + n->val.boolval.type = T_Boolean; + n->val.boolval.boolval = true; + n->location = -1; + restarget->name = pstrdup(name); + restarget->indirection = NIL; + restarget->val = (Node *) n; + restarget->location = -1; + restargets = lappend((List *) restargets, restarget); + } + } + + if (list_length(restargets) >= 1) + { + /* add missing DEFINEs */ + windef->rpCommonSyntax->rpDefs = + list_concat(windef->rpCommonSyntax->rpDefs, restargets); + list_free(restargets); + } + + /* + * Check for duplicate row pattern definition variables. The standard + * requires that no two row pattern definition variable names shall be + * equivalent. + */ + restargets = NIL; + foreach(lc, windef->rpCommonSyntax->rpDefs) + { + restarget = (ResTarget *) lfirst(lc); + name = restarget->name; + + /* + * Add DEFINE expression (Restarget->val) to the targetlist as a + * TargetEntry if it does not exist yet. Planner will add the column + * ref var node to the outer plan's target list later on. This makes + * DEFINE expression could access the outer tuple while evaluating + * PATTERN. + * + * XXX: adding whole expressions of DEFINE to the plan.targetlist is + * not so good, because it's not necessary to evalute the expression + * in the target list while running the plan. We should extract the + * var nodes only then add them to the plan.targetlist. + */ + findTargetlistEntrySQL99(pstate, (Node *) restarget->val, + targetlist, EXPR_KIND_RPR_DEFINE); + + /* + * Make sure that the row pattern definition search condition is a + * boolean expression. + */ + transformWhereClause(pstate, restarget->val, + EXPR_KIND_RPR_DEFINE, "DEFINE"); + + foreach(l, restargets) + { + char *n; + + r = (ResTarget *) lfirst(l); + n = r->name; + + if (!strcmp(n, name)) + ereport(ERROR, + (errcode(ERRCODE_SYNTAX_ERROR), + errmsg("row pattern definition variable name \"%s\" appears more than once in DEFINE clause", + name), + parser_errposition(pstate, exprLocation((Node *) r)))); + } + restargets = lappend(restargets, restarget); + } + list_free(restargets); + + /* + * Create list of row pattern DEFINE variable name's initial. We assign + * [a-z] to them (up to 26 variable names are allowed). + */ + restargets = NIL; + i = 0; + initialLen = strlen(defineVariableInitials); + + foreach(lc, windef->rpCommonSyntax->rpDefs) + { + char initial[2]; + + restarget = (ResTarget *) lfirst(lc); + name = restarget->name; + + if (i >= initialLen) + { + ereport(ERROR, + (errcode(ERRCODE_SYNTAX_ERROR), + errmsg("number of row pattern definition variable names exceeds %d", + initialLen), + parser_errposition(pstate, + exprLocation((Node *) restarget)))); + } + initial[0] = defineVariableInitials[i++]; + initial[1] = '\0'; + wc->defineInitial = lappend(wc->defineInitial, + makeString(pstrdup(initial))); + } + + defineClause = transformTargetList(pstate, windef->rpCommonSyntax->rpDefs, + EXPR_KIND_RPR_DEFINE); + + /* mark column origins */ + markTargetListOrigins(pstate, defineClause); + + /* mark all nodes in the DEFINE clause tree with collation information */ + assign_expr_collations(pstate, (Node *) defineClause); + + return defineClause; +} + +/* + * transformPatternClause + * Process PATTERN clause and return PATTERN clause in the raw parse tree + */ +static void +transformPatternClause(ParseState *pstate, WindowClause *wc, + WindowDef *windef) +{ + ListCell *lc; + + /* + * Row Pattern Common Syntax clause exists? + */ + if (windef->rpCommonSyntax == NULL) + return; + + wc->patternVariable = NIL; + wc->patternRegexp = NIL; + foreach(lc, windef->rpCommonSyntax->rpPatterns) + { + A_Expr *a; + char *name; + char *regexp; + + if (!IsA(lfirst(lc), A_Expr)) + ereport(ERROR, + errmsg("node type is not A_Expr")); + + a = (A_Expr *) lfirst(lc); + name = strVal(a->lexpr); + + wc->patternVariable = lappend(wc->patternVariable, makeString(pstrdup(name))); + regexp = strVal(lfirst(list_head(a->name))); + + wc->patternRegexp = lappend(wc->patternRegexp, makeString(pstrdup(regexp))); + } +} + +/* + * transformMeasureClause + * Process MEASURE clause + * XXX MEASURE clause is not supported yet + */ +static List * +transformMeasureClause(ParseState *pstate, WindowClause *wc, + WindowDef *windef) +{ + if (windef->rowPatternMeasures == NIL) + return NIL; + + ereport(ERROR, + (errcode(ERRCODE_SYNTAX_ERROR), + errmsg("%s", "MEASURE clause is not supported yet"), + parser_errposition(pstate, exprLocation((Node *) windef->rowPatternMeasures)))); + return NIL; +} diff --git a/src/backend/parser/parse_expr.c b/src/backend/parser/parse_expr.c index c2806297aa..e827c59fd4 100644 --- a/src/backend/parser/parse_expr.c +++ b/src/backend/parser/parse_expr.c @@ -575,6 +575,7 @@ transformColumnRef(ParseState *pstate, ColumnRef *cref) case EXPR_KIND_COPY_WHERE: case EXPR_KIND_GENERATED_COLUMN: case EXPR_KIND_CYCLE_MARK: + case EXPR_KIND_RPR_DEFINE: /* okay */ break; @@ -1858,6 +1859,9 @@ transformSubLink(ParseState *pstate, SubLink *sublink) case EXPR_KIND_GENERATED_COLUMN: err = _("cannot use subquery in column generation expression"); break; + case EXPR_KIND_RPR_DEFINE: + err = _("cannot use subquery in DEFINE expression"); + break; /* * There is intentionally no default: case here, so that the @@ -3197,6 +3201,8 @@ ParseExprKindName(ParseExprKind exprKind) return "GENERATED AS"; case EXPR_KIND_CYCLE_MARK: return "CYCLE"; + case EXPR_KIND_RPR_DEFINE: + return "DEFINE"; /* * There is intentionally no default: case here, so that the diff --git a/src/backend/parser/parse_func.c b/src/backend/parser/parse_func.c index 9b23344a3b..4c482abb30 100644 --- a/src/backend/parser/parse_func.c +++ b/src/backend/parser/parse_func.c @@ -2658,6 +2658,9 @@ check_srf_call_placement(ParseState *pstate, Node *last_srf, int location) case EXPR_KIND_CYCLE_MARK: errkind = true; break; + case EXPR_KIND_RPR_DEFINE: + errkind = true; + break; /* * There is intentionally no default: case here, so that the -- 2.25.1 ----Next_Part(Thu_Dec_19_15_19_50_2024_894)-- Content-Type: Text/X-Patch; charset=us-ascii Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="v24-0003-Row-pattern-recognition-patch-rewriter.patch" ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
* [PATCH 1/2] Demonstrate possible race conditions in logical decoding. @ 2026-01-19 11:54 Antonin Houska <[email protected]> 0 siblings, 0 replies; 486+ messages in thread From: Antonin Houska @ 2026-01-19 11:54 UTC (permalink / raw) The problem is that the snapshot builder can create a snapshot before CLOG has been updated. That breaks visibility check that use such snapshot. For more details, see startup_race.spec. Success of the test means that the problem is present. Thus it would need to be modified if it should be merged into the tree. Another problem that currently prevents this test from being merged is that it hard-wires the logical decoding setup into the SET TRANSACTION command. I tried to modify the isolation tester so it can use the logical replication protocol (in which case the test could use the "CREATE_REPLICATION_SNAPSHOT ... (SNAPSHOT 'use')" command), but the tester does things that are not compatible with that protocol (e.g. it sets the application_name parameter). --- .../test_decoding/expected/startup_race.out | 85 ++++++++++++ contrib/test_decoding/specs/startup_race.spec | 126 ++++++++++++++++++ src/backend/access/transam/xact.c | 6 + src/backend/replication/logical/snapbuild.c | 3 + src/backend/utils/time/snapmgr.c | 66 +++++++++ src/include/utils/snapmgr.h | 1 + 6 files changed, 287 insertions(+) create mode 100644 contrib/test_decoding/expected/startup_race.out create mode 100644 contrib/test_decoding/specs/startup_race.spec diff --git a/contrib/test_decoding/expected/startup_race.out b/contrib/test_decoding/expected/startup_race.out new file mode 100644 index 00000000000..597fa617831 --- /dev/null +++ b/contrib/test_decoding/expected/startup_race.out @@ -0,0 +1,85 @@ +Parsed test spec with 6 sessions + +starting permutation: s1_assign_xid s2_set_snapshot s3_assign_xid s1_rollback s3_rollback s4_do_changes s5_wake_up_full_snapshot s2_scan s2_rollback s5_wake_up_before_clog s6_check +injection_points_attach +----------------------- + +(1 row) + +injection_points_attach +----------------------- + +(1 row) + +step s1_assign_xid: + BEGIN; + CREATE TABLE b(i int); + +step s2_set_snapshot: + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; + <waiting ...> +step s3_assign_xid: + BEGIN; + CREATE TABLE c(i int); + +step s1_rollback: + ROLLBACK; + +step s3_rollback: + ROLLBACK; + +step s4_do_changes: + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; + <waiting ...> +step s5_wake_up_full_snapshot: + SELECT injection_points_wakeup('snapbuild-full-snapshot'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s2_set_snapshot: <... completed> +step s2_scan: + TABLE a; + +i|j +-+- +1|1 +2|2 +(2 rows) + +step s2_rollback: + ROLLBACK; + +step s5_wake_up_before_clog: + SELECT injection_points_wakeup('before-clog-update'); + +injection_points_wakeup +----------------------- + +(1 row) + +step s4_do_changes: <... completed> +step s6_check: + SELECT * FROM a ORDER BY i; + +i|j +-+- +1|1 +2|2 +(2 rows) + +injection_points_detach +----------------------- + +(1 row) + +injection_points_detach +----------------------- + +(1 row) + diff --git a/contrib/test_decoding/specs/startup_race.spec b/contrib/test_decoding/specs/startup_race.spec new file mode 100644 index 00000000000..8f67e07fa7a --- /dev/null +++ b/contrib/test_decoding/specs/startup_race.spec @@ -0,0 +1,126 @@ +setup +{ + CREATE TABLE a(i int primary key, j int) WITH (autovacuum_enabled = off); + INSERT INTO a(i, j) VALUES (1, 1), (2, 2); + CREATE EXTENSION injection_points; +} + +session s1 +step s1_assign_xid +{ + BEGIN; + CREATE TABLE b(i int); +} +step s1_rollback +{ + ROLLBACK; +} + +session s2 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('snapbuild-full-snapshot', 'wait'); +} +# Use special, hard-wired snapshot name to set the initial snapshot from +# logical replication slot. +step s2_set_snapshot +{ + BEGIN READ ONLY ISOLATION LEVEL REPEATABLE READ; + SET TRANSACTION SNAPSHOT 'from_slot'; +} +# Perform the scan. +step s2_scan +{ + TABLE a; +} +step s2_rollback +{ + ROLLBACK; +} +teardown +{ + SELECT injection_points_detach('snapbuild-full-snapshot'); +} + +session s3 +step s3_assign_xid +{ + BEGIN; + CREATE TABLE c(i int); +} +step s3_rollback +{ + ROLLBACK; +} + +session s4 +setup +{ + SELECT injection_points_set_local(); + SELECT injection_points_attach('before-clog-update', 'wait'); +} +step s4_do_changes +{ + INSERT INTO a(i, j) VALUES (3, 3); + UPDATE a SET j = j + 1 WHERE i = 1; + DELETE FROM a WHERE i = 2; +} +teardown +{ + SELECT injection_points_detach('before-clog-update'); +} + +session s5 +step s5_wake_up_full_snapshot +{ + SELECT injection_points_wakeup('snapbuild-full-snapshot'); +} +step s5_wake_up_before_clog +{ + SELECT injection_points_wakeup('before-clog-update'); +} + +session s6 +step s6_check +{ + SELECT * FROM a ORDER BY i; +} + +permutation +# Let the snapshot builder go through all the states. The problematic case +# happens in the FULL_SNAPSHOT. +s1_assign_xid +# This should leave the builder in BUILDING_SNAPSHOT, waiting for the active +# transaction to end. +s2_set_snapshot +# Make sure that s1_rollback does not allow going to CONSISTENT directly. +s3_assign_xid +# Let the builder proceed to FULL_SNAPSHOT. It should stop at the injection +# point 'snapbuild-full-snapshot'. +s1_rollback +# The transaction of s3 is not needed anymore, CONSISTENT should be the next +# stage. +s3_rollback +# Perform data changes before the snapshot builder triggers creation of the +# RUNNING_XACTS record. This will stop before setting transaction status in +# CLOG. +s4_do_changes +# Unblock the injection point so that the snapshot can finally be created. +s5_wake_up_full_snapshot +# Use the snapshot for a scan. The snapshot will consider s4 not running +# anymore, however CLOG is not aware of the commit yet. Thus +# HeapTupleSatisfiesMVCC will consider the transaction aborted. In particular, +# for UPDATE, if both xmax of the old version and xmin of the new version are +# considered aborted, so the effects of the UPDATE are lost +# altogether. Similarly, INSERT and DELETE have no effect because the xmin +# transaction of the inserted tuple and xmax of the deleted tuple are +# considered aborted +s2_scan +s2_rollback +# CLOG can be updated now. +s5_wake_up_before_clog +# Scan the table again using a new transaction, with a normal transaction +# snapshot. The results are still wrong due to hint bits set incorrectly. +s6_check + diff --git a/src/backend/access/transam/xact.c b/src/backend/access/transam/xact.c index c857e23552f..2fea45b2fed 100644 --- a/src/backend/access/transam/xact.c +++ b/src/backend/access/transam/xact.c @@ -65,6 +65,7 @@ #include "utils/builtins.h" #include "utils/combocid.h" #include "utils/guc.h" +#include "utils/injection_point.h" #include "utils/inval.h" #include "utils/memutils.h" #include "utils/relmapper.h" @@ -1348,6 +1349,9 @@ RecordTransactionCommit(void) &RelcacheInitFileInval); wrote_xlog = (XactLastRecEnd != 0); + /* Load the injection point before entering the critical section */ + INJECTION_POINT_LOAD("before-clog-update"); + /* * If we haven't been assigned an XID yet, we neither can, nor do we want * to write a COMMIT record. @@ -1514,6 +1518,8 @@ RecordTransactionCommit(void) { XLogFlush(XactLastRecEnd); + INJECTION_POINT_CACHED("before-clog-update", NULL); + /* * Now we may update the CLOG, if we wrote a COMMIT record above */ diff --git a/src/backend/replication/logical/snapbuild.c b/src/backend/replication/logical/snapbuild.c index 7f79621b57e..9b09dc8eac1 100644 --- a/src/backend/replication/logical/snapbuild.c +++ b/src/backend/replication/logical/snapbuild.c @@ -141,6 +141,7 @@ #include "storage/procarray.h" #include "storage/standby.h" #include "utils/builtins.h" +#include "utils/injection_point.h" #include "utils/memutils.h" #include "utils/snapmgr.h" #include "utils/snapshot.h" @@ -1387,6 +1388,8 @@ SnapBuildFindSnapshot(SnapBuild *builder, XLogRecPtr lsn, xl_running_xacts *runn errdetail("Waiting for transactions (approximately %d) older than %u to end.", running->xcnt, running->nextXid)); + INJECTION_POINT("snapbuild-full-snapshot", NULL); + SnapBuildWaitSnapshot(running, running->nextXid); } diff --git a/src/backend/utils/time/snapmgr.c b/src/backend/utils/time/snapmgr.c index 2e6197f5f35..f327b779004 100644 --- a/src/backend/utils/time/snapmgr.c +++ b/src/backend/utils/time/snapmgr.c @@ -110,10 +110,13 @@ #include "access/subtrans.h" #include "access/transam.h" #include "access/xact.h" +#include "access/xlogutils.h" #include "datatype/timestamp.h" #include "lib/pairingheap.h" #include "miscadmin.h" #include "port/pg_lfind.h" +#include "replication/logical.h" +#include "replication/snapbuild.h" #include "storage/fd.h" #include "storage/predicate.h" #include "storage/proc.h" @@ -1421,6 +1424,17 @@ ImportSnapshot(const char *idstr) (errcode(ERRCODE_FEATURE_NOT_SUPPORTED), errmsg("a snapshot-importing transaction must have isolation level SERIALIZABLE or REPEATABLE READ"))); + if (strcmp(idstr, "from_slot") == 0) + { + Snapshot snap; + + snap = create_test_snapshot(); + /* XXX sourcevxid shouldn't be needed in this special case */ + SetTransactionSnapshot(snap, NULL, MyProcPid, MyProc); + + return; + } + /* * Verify the identifier: only 0-9, A-F and hyphens are allowed. We do * this mainly to prevent reading arbitrary files. @@ -1969,3 +1983,55 @@ ResOwnerReleaseSnapshot(Datum res) { UnregisterSnapshotNoOwner((Snapshot) DatumGetPointer(res)); } + +/* + * CreateReplicationSlot() with the CRS_USE_SNAPSHOT option would be useful + * for testing, but regression tests cannot speak both replication and query + * protocol at the same time. This function can be used instead to create a + * snapshot for special tests of logical replication. + */ +Snapshot +create_test_snapshot(void) +{ + const char *slotname = "test_slot"; + const char *plugin; + LogicalDecodingContext *ctx; + Snapshot snap; + + /* + * XXX Hard-wired values are fine for the special test that needs this + * function. + */ + plugin = "test_decoding"; + + Assert(!MyReplicationSlot); + + CheckLogicalDecodingRequirements(); + + ReplicationSlotCreate(slotname, true, RS_TEMPORARY, + false, false, false); + + /* + * Ensure the logical decoding is enabled before initializing the + * logical decoding context. + */ + EnsureLogicalDecodingEnabled(); + Assert(IsLogicalDecodingEnabled()); + + ctx = CreateInitDecodingContext(plugin, NIL, true, + InvalidXLogRecPtr, + XL_ROUTINE(.page_read = read_local_xlog_page, + .segment_open = wal_segment_open, + .segment_close = wal_segment_close), + NULL, NULL, NULL); + + /* build initial snapshot, might take a while */ + DecodingContextFindStartpoint(ctx); + + /* Do what the function is called for. */ + snap = SnapBuildInitialSnapshot(ctx->snapshot_builder); + snap = CopySnapshot(snap); + FreeDecodingContext(ctx); + + return snap; +} diff --git a/src/include/utils/snapmgr.h b/src/include/utils/snapmgr.h index b8c01a291a1..9f0d60ebc1b 100644 --- a/src/include/utils/snapmgr.h +++ b/src/include/utils/snapmgr.h @@ -123,4 +123,5 @@ extern Snapshot RestoreSnapshot(char *start_address); struct PGPROC; extern void RestoreTransactionSnapshot(Snapshot snapshot, struct PGPROC *source_pgproc); +extern Snapshot create_test_snapshot(void); #endif /* SNAPMGR_H */ -- 2.47.3 --=-=-=-- ^ permalink raw reply [nested|flat] 486+ messages in thread
end of thread, other threads:[~2026-01-19 11:54 UTC | newest] Thread overview: 486+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2019-05-10 02:22 [PATCH v3 11/12] s/recommendable/recommended Justin Pryzby <[email protected]> 2019-05-10 02:22 [PATCH v5 12/12] s/recommendable/recommended Justin Pryzby <[email protected]> 2024-12-19 06:06 [PATCH v24 2/8] Row pattern recognition patch (parse/analysis). Tatsuo Ishii <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]> 2026-01-19 11:54 [PATCH 1/2] Demonstrate possible race conditions in logical decoding. Antonin Houska <[email protected]>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox