Re: PG18: use-after-free in exec partition pruning after an EPQ recheck in LockRows

From: Andrey Rachitskiy <pl0h0yp1(at)gmail(dot)com>
To: David Rowley <dgrowleyml(at)gmail(dot)com>
Cc: Vladimir Savin <vladimir(at)encord(dot)com>, pgsql-bugs(at)lists(dot)postgresql(dot)org
Subject: Re: PG18: use-after-free in exec partition pruning after an EPQ recheck in LockRows
Date: 2026-10-08 08:30:07
Message-ID: CAB8bMituD9yuWp1-EOkG7ohLv32zRX0oF=huXrvf-24C89rXvg@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

чт, 8 окт. 2026 г. в 13:08, David Rowley <dgrowleyml(at)gmail(dot)com>:

> On Fri, 2 Oct 2026 at 05:16, Andrey Rachitskiy <pl0h0yp1(at)gmail(dot)com> wrote:
> > Skip InitExecPartitionPruneContexts() when es_epq_active is set. A
> > case is added to eval-plan-qual.
>
> uhh, that's a pretty horrible fix. So partition pruning needs to know
> what EPQ is now?
>
> I think it would be much better to fix with the attached, which adds
> an "initialized" flag to the PartitionPruneState.
>
>
Hi David!

Thanks for the review.

Agreed. Skipping on es_epq_active was answering the wrong question.
The invariant is that InitExecPartitionPruneContexts() must not run
twice on a shared PartitionPruneState.
Your initialized flag is the right fix.

LGTM

--
Regards,
Rachitskiy Andrey

In response to

Browse pgsql-bugs by date

  From Date Subject
Previous Message Dmitry Dolgov 2026-10-08 08:09:26 Re: BUG #19735: `jsonb_object_agg_unique_strict` drops a JSONB `null` value as if it were SQL NULL