Re: BUG #19631: currtid2() on a view with GROUP BY ctid crashes with XX000

From: Ayush Tiwari <ayushtiwari(dot)slg01(at)gmail(dot)com>
To: hackerzheng666(at)gmail(dot)com, pgsql-bugs(at)lists(dot)postgresql(dot)org
Subject: Re: BUG #19631: currtid2() on a view with GROUP BY ctid crashes with XX000
Date: 2026-08-21 10:15:14
Message-ID: CAJTYsWVYYpxOx29jxrR4SzYMGzJtENr4iQ53NvVE3uzCFtVkrQ@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

Hi,

On Wed, 19 Aug 2026 at 16:16, Ayush Tiwari <ayushtiwari(dot)slg01(at)gmail(dot)com>
wrote:

> Hi,
>
> On Wed, 19 Aug 2026 at 14:54, PG Bug reporting form <
> noreply(at)postgresql(dot)org> wrote:
>
>> The following bug has been logged on the website:
>>
>> Bug reference: 19631
>> Logged by: Zheng Hacker
>> Email address: hackerzheng666(at)gmail(dot)com
>> PostgreSQL version: 19beta3
>> Operating system: Linux x86_64
>> Description:
>>
>> PostgreSQL version: 20devel (commit bdbf662, 2026-08-19)
>> OS: Linux x86_64
>>
>> Calling currtid2() on a view whose SELECT includes ctid in a GROUP BY
>> hits elog(ERROR) without errcode() in tid.c, producing SQLSTATE XX000.
>>
>> Reproducer:
>>
>> CREATE TABLE tid_tab (a int);
>> INSERT INTO tid_tab VALUES (1);
>> CREATE VIEW tid_view_with_ctid AS
>> SELECT ctid, a FROM tid_tab GROUP BY ctid, a;
>> SELECT currtid2('tid_view_with_ctid'::text, '(0,1)'::tid);
>> -- ERROR: XX000: currtid cannot handle this view
>> -- LOCATION: currtid_for_view, tid.c:435
>>
>> Note: the view has a ctid column (so it passes the tididx check at
>> line 389 which does have a proper errcode), but the GROUP BY prevents
>> the code from resolving the TLE to a simple base-table Var, so it
>> falls through to the elog(ERROR) at line 435 which lacks errcode().
>>
>> Expected: a proper SQLSTATE (e.g. 0A000 feature_not_supported).
>>
>> Found by automated SQL fuzzing.
>> Credit: Zheng Wang, Yanjie Zhao, Yiyang Liu
>>
>
> Thanks for the reports. #19629, #19630 and #19631 share one cause: an
> error ordinary SQL can reach is raised without an errcode(), so the user
> sees XX000.
>
> I scanned the backend for the same pattern, and the attached patch fixes
> those three plus four more sites with the same problem: unicode_assigned()
> on a non-UTF8 encoding, the pg_control_*() CRC check, a GiST tuple marked
> invalid, and ALTER COLLATION ... REFRESH VERSION on "default".
>

Attaching new patch addressing just #19631 along with
rest files mentioned upthread.

Regards,
Ayush

Attachment Content-Type Size
v1-0001-Fix-internal-errors-reachable-from-SQL.patch application/octet-stream 6.1 KB

In response to

Browse pgsql-bugs by date

  From Date Subject
Next Message Álvaro Herrera 2026-08-21 11:34:11 Re: BUG #19632: RULE rewriting crashes with XX000 when RETURNING old/new references a system column
Previous Message Zsolt Parragi 2026-08-21 09:36:34 Re: MERGE/SPLIT PARTITIONS issues/questions