pgsql: Fix VM clear WAL logging by registering VM blocks

From: Melanie Plageman <melanieplageman(at)gmail(dot)com>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Fix VM clear WAL logging by registering VM blocks
Date: 2026-07-15 21:32:48
Message-ID: E1wk7Dk-000M0Z-0R@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Fix VM clear WAL logging by registering VM blocks

Heap WAL records that clear bits on the visibility map (like inserts and
deletes) did not register the visibility map blocks they modified.
Because the WAL summarizer only records registered blocks, an
incremental backup taken over such operations would omit the changed VM
pages. On restore, the VM would retain stale all-visible/all-frozen
bits, which can cause wrong results from index-only scans and incorrect
relfrozenxid advancement due to vacuum page skipping.

Not registering the VM buffer also meant we never emitted FPIs of VM
pages when clearing bits. A torn VM page won't raise an error because
the VM is read with ZERO_ON_ERROR; with checksums on, it would be
detected and zeroed, but with checksums off, it is accepted as-is and
can lead to data corruption.

Fix this by registering the VM buffer in the WAL record when clearing VM
bits. The VM buffer must now be locked throughout the critical section
that modifies the VM and heap pages and emits the WAL record. This can
slow down operations that clear the VM, since the VM lock is held longer
and VM FPIs may be emitted, but it is required for correctness.

Note that this fix does not repair existing incremental backups.

Bumps XLOG_PAGE_MAGIC. Though it is late in the cycle (post-beta 2) to
be doing so, that seemed better than maintaining the backwards
compatability code in yet another branch.

Author: Melanie Plageman <melanieplageman(at)gmail(dot)com>
Author: Andres Freund <andres(at)anarazel(dot)de>
Reviewed-by: Robert Haas <robertmhaas(at)gmail(dot)com>
Reviewed-by: Andrey Borodin <x4mmm(at)yandex-team(dot)ru>
Discussion: https://postgr.es/m/flat/CAAKRu_bn%2Be7F4yPFBgFbnP%2BsyJRKyNK092bjD2LKvZW7O4Svag>
Backpatch-through: 17

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/b01c31eef9c3a83d0bd9f30656cedaa6722890ee

Modified Files
--------------
contrib/pg_surgery/heap_surgery.c | 40 +++-
src/backend/access/heap/heapam.c | 371 ++++++++++++++++++++++++++------
src/backend/access/heap/heapam_xlog.c | 202 +++++++++++------
src/backend/access/heap/pruneheap.c | 2 +
src/backend/access/heap/visibilitymap.c | 24 ++-
src/bin/pg_walsummary/t/002_blocks.pl | 7 +-
src/include/access/heapam_xlog.h | 17 +-
src/include/access/xlog_internal.h | 2 +-
8 files changed, 508 insertions(+), 157 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Melanie Plageman 2026-07-15 21:32:49 pgsql: Test that VM clear registers VM buffers
Previous Message Melanie Plageman 2026-07-15 21:25:51 pgsql: Make VM clear take a RelFileLocator and not fake relcache