pgsql: Fix possible crash when RI fast-path metadata is invalidated mid

From: Amit Langote <amitlan(at)postgresql(dot)org>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Fix possible crash when RI fast-path metadata is invalidated mid
Date: 2026-10-06 00:04:57
Message-ID: E1xDsfx-00000000ThE-1EbE@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Fix possible crash when RI fast-path metadata is invalidated mid-check

ri_FastPathCheck() read riinfo->fpmeta again after
ri_CheckFunctionPermissions(), which looks up catalog entries and so
can process invalidation messages. If one of them reaches
InvalidateConstraintCacheCallBack() for the constraint, as a pg_amop
change or a cache reset would, the callback detaches the metadata and
sets riinfo->fpmeta to NULL, which build_index_scankeys() then
dereferences.

The callback already defers freeing detached metadata until
AtEOXact_RI(), and its comment assumes callers keep their own pointer
to it, so use a local pointer instead of riinfo->fpmeta.

There is no test, as hitting this needs an invalidation to arrive
during those catalog lookups.

Discussion: https://postgr.es/m/CA+HiwqFaipkMsZ8XP-9sMk21h0Q7rih=NpJQXsBAaD39VtnrOA@mail.gmail.com

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/ad3b33d7824e3c49699ace1788acb1b07bfa69f1

Modified Files
--------------
src/backend/utils/adt/ri_triggers.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Amit Langote 2026-10-06 00:05:10 pgsql: Fix possible crash when RI fast-path metadata is invalidated mid
Previous Message Richard Guo 2026-10-05 23:52:21 pgsql: Don't pass grouped relations to FDWs