| From: | Peter Geoghegan <pg(at)bowt(dot)ie> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Rescind unsafe deduplication support. |
| Date: | 2026-10-06 22:22:14 |
| Message-ID: | E1xEDY6-00000000bir-3sNU@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Rescind unsafe deduplication support.
bpchar equality ignores trailing spaces, so equal values in a column
with no length specifier can have different images. Similarly,
oidvector equality intentionally pays no attention to the array lower
bound field. We nevertheless allowed nbtree deduplication to be used
with indexes built with bpchar_ops, bpchar_pattern_ops, or
oidvector_ops. A posting list split could therefore place a TID in an
index tuple whose key was equal to, but not bytewise identical to, the
corresponding table value. This allowed index-only scans to return
subtly wrong results.
To fix, drop support function 4 from the affected opclasses (we can't
change catalog contents on branches 14 through 18, so we just disable
deduplication by adding hard-coding to the relevant support functions).
Deliberately leave the oidvector opclass alone on branches 14 through
18, though. Disallowing oidvector deduplication on these branches would
make pg_amcheck report that pg_proc_proname_args_nsp_index has a corrupt
metapage, needlessly alarming users.
System catalog oidvector values always have a lower bound of 0, so the
issue can't cause harm there; a user can only hit it by indexing an
oidvector column that stores the output of a function like trim_array().
It seems very unlikely that any user would ever do that.
Users should REINDEX any B-Tree index on a bpchar column.
Author: Shihao Zhong <zhong950419(at)gmail(dot)com>
Co-authored-by: Peter Geoghegan <pg(at)bowt(dot)ie>
Reported-by: Ke <kehan5800(at)gmail(dot)com>
Reported-by: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Reviewed-by: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Bug: #19749
Discussion: https://postgr.es/m/19749-d46adf7c7d910b07@postgresql.org
Discussion: https://postgr.es/m/CAGRkXqQQ311Lg=62x5UdZtPuRFgpT6XpPMw4X9E3tgbTu162Mw@mail.gmail.com
Backpatch-through: 14
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/18740523a4a044a969f71a7322fb2d19ca69d00d
Modified Files
--------------
contrib/amcheck/verify_nbtree.c | 17 +------------
doc/src/sgml/btree.sgml | 16 +++++++++----
src/include/catalog/catversion.h | 2 +-
src/include/catalog/pg_amproc.dat | 7 ------
src/test/regress/expected/btree_index.out | 2 --
src/test/regress/expected/opr_sanity.out | 40 ++++++++++++++++---------------
src/test/regress/sql/btree_index.sql | 3 ---
7 files changed, 35 insertions(+), 52 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Peter Geoghegan | 2026-10-06 22:22:15 | pgsql: Rescind unsafe deduplication support. |
| Previous Message | Nathan Bossart | 2026-10-06 19:34:48 | pgsql: Use a non-locking initial test in TAS_SPIN on AArch64. |