| From: | Amit Langote <amitlan(at)postgresql(dot)org> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Fix possible crash when RI fast-path metadata is invalidated mid |
| Date: | 2026-10-06 00:04:57 |
| Message-ID: | E1xDsfx-00000000ThE-1EbE@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Fix possible crash when RI fast-path metadata is invalidated mid-check
ri_FastPathCheck() read riinfo->fpmeta again after
ri_CheckFunctionPermissions(), which looks up catalog entries and so
can process invalidation messages. If one of them reaches
InvalidateConstraintCacheCallBack() for the constraint, as a pg_amop
change or a cache reset would, the callback detaches the metadata and
sets riinfo->fpmeta to NULL, which build_index_scankeys() then
dereferences.
The callback already defers freeing detached metadata until
AtEOXact_RI(), and its comment assumes callers keep their own pointer
to it, so use a local pointer instead of riinfo->fpmeta.
There is no test, as hitting this needs an invalidation to arrive
during those catalog lookups.
Discussion: https://postgr.es/m/CA+HiwqFaipkMsZ8XP-9sMk21h0Q7rih=NpJQXsBAaD39VtnrOA@mail.gmail.com
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/ad3b33d7824e3c49699ace1788acb1b07bfa69f1
Modified Files
--------------
src/backend/utils/adt/ri_triggers.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Amit Langote | 2026-10-06 00:05:10 | pgsql: Fix possible crash when RI fast-path metadata is invalidated mid |
| Previous Message | Richard Guo | 2026-10-05 23:52:21 | pgsql: Don't pass grouped relations to FDWs |