| From: | Amit Langote <amitlan(at)postgresql(dot)org> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Fix possible crash when RI fast-path metadata is invalidated mid |
| Date: | 2026-10-06 00:05:10 |
| Message-ID: | E1xDsgA-00000000Ths-2WHj@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Fix possible crash when RI fast-path metadata is invalidated mid-check
ri_FastPathCheck() read riinfo->fpmeta again after
ri_CheckFunctionPermissions(), which looks up catalog entries and so
can process invalidation messages. If one of them reaches
InvalidateConstraintCacheCallBack() for the constraint, as a pg_amop
change or a cache reset would, the callback detaches the metadata and
sets riinfo->fpmeta to NULL, which build_index_scankeys() then
dereferences.
The callback already defers freeing detached metadata until
AtEOXact_RI(), and its comment assumes callers keep their own pointer
to it, so use a local pointer instead of riinfo->fpmeta.
There is no test, as hitting this needs an invalidation to arrive
during those catalog lookups.
Discussion: https://postgr.es/m/CA+HiwqFaipkMsZ8XP-9sMk21h0Q7rih=NpJQXsBAaD39VtnrOA@mail.gmail.com
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/e73e0196d30198e4579656881497f057788bb53d
Modified Files
--------------
src/backend/utils/adt/ri_triggers.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Tom Lane | 2026-10-06 00:40:59 | pgsql: Doc: remove stray right brace in TRANSFORM option syntax summari |
| Previous Message | Amit Langote | 2026-10-06 00:04:57 | pgsql: Fix possible crash when RI fast-path metadata is invalidated mid |