| From: | Mark Dilger <mark(dot)dilger(at)enterprisedb(dot)com> |
|---|---|
| To: | Andrey Borodin <x4mmm(at)yandex-team(dot)ru> |
| Cc: | pgsql-hackers mailing list <pgsql-hackers(at)lists(dot)postgresql(dot)org> |
| Subject: | Re: amcheck: detect corruption from the recent snapshot-export bug |
| Date: | 2026-10-05 14:41:28 |
| Message-ID: | CAHgHdKudkQALPDfnuZXzgkkz=Sj3GjOYYAap0+tSsMNL=GfJ=A@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
On Sun, Oct 4, 2026 at 6:51 AM Andrey Borodin <x4mmm(at)yandex-team(dot)ru> wrote:
> Hi hackers!
>
> I was investigating foreign-key violations reported by a user after
> failover. Some tuples had HEAP_XMIN_INVALID set despite their xmin being
> committed in pg_xact. During the investigation I found the recent
> snapshot-export bug thread [0], with a fix already committed.
>
> pg_visibility reported the affected tuples on the standby, but
> verify_heapam() did not. We routinely run verify_heapam() and would like
> it to catch this damage without having to scan the same tables again
> with pg_visibility.
>
> PFA a two-patch series. 0001 detects this damage by reporting
> HEAP_XMIN_INVALID when xmin is known to have committed. It excludes
> old-style VACUUM FULL tuples and does not treat an assumed commit after
> pg_xact truncation as evidence of corruption.
>
This also affects HEAP_XMAX_INVALID for committed deletions.
> I think it would be good to have such check backpatched along with the
> corruption fix.
>
> 0002 revisits the related xmin/xmax checks I proposed in 2024 [1]. It
> checks committed hints against aborted transactions, and invalid xmax
> hints against committed updaters, including multixact members. I kept
> these separate so that we can address the known corruption first.
>
> The first patch's test also covers HEAP_MOVED_IN, though I'm not sure
> it's worth adding coverage for this old VACUUM FULL format.
>
A minor nit: the new error messages do not follow existing style.
I believe this patch set fixes a real bug. Thanks for finding it.
-- Mark Dilger
| From | Date | Subject | |
|---|---|---|---|
| Next Message | shihao zhong | 2026-10-05 14:56:41 | Re: pg_resetwal: refuse to run when backup_label exists |
| Previous Message | Matthias van de Meent | 2026-10-05 14:39:17 | Re: Let an ordering index scan hand its ORDER BY value to the target list |