| From: | Michael Paquier <michael(at)paquier(dot)xyz> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Fix WAL segment fd leaks with the WAL reading facility (xlogread |
| Date: | 2026-10-08 03:12:59 |
| Message-ID: | E1xEeZ1-00000000lXB-0rlK@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Fix WAL segment fd leaks with the WAL reading facility (xlogreader.c/h)
In most of the backend code, XLogReaders open a WAL segment file with
BasicOpenFile() (xlogutils.c, WAL summarizer and WAL sender). On ERROR,
the opened file descriptor could leak while reading WAL segments, piling
them over time if a session can spawn XLogReaders at will, leading to
EMFILE with various consequences, the worst being a backend-side PANIC.
The problem has been reported as reachable with pg_walinspect (EXECUTE
privilege revoked from PUBLIC by default), or replication slot functions
(REPLICATION privilege required).
XLogReaderState gains a memory context reset callback, registered if a
segment_open callback has the idea to open a WAL segment with
BasicOpenFile(). XLogReaderRegisterResetCallback() can be used by a
segment_open callback to ensure the cleanup of any opened file
descriptor.
No backpatch is done. This breaks the ABI of XLogReaderState (sizeof),
and MemoryContextUnregisterResetCallback() is new in v19. There may be
an argument for fixing this issue in v19, but the release is close
enough that this change does not seem worth taking a risk for.
Author: Bharath Rupireddy <bharath(dot)rupireddyforpostgres(at)gmail(dot)com>
Reviewed-by: Bertrand Drouvot <bertranddrouvot(dot)pg(at)gmail(dot)com>
Reviewed-by: Sami Imseih <samimseih(dot)pg(at)gmail(dot)com>
Reviewed-by: Chao Li <li(dot)evan(dot)chao(at)gmail(dot)com>
Reviewed-by: Michael Paquier <michael(at)paquier(dot)xyz>
Discussion: https://postgr.es/m/CALj2ACVwDuOXXDjj2cVdnTKoxsgTSLDin4XoL63AnM6aUgMQaA@mail.gmail.com
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/cb1eef81c9bc8d1a2adc1e3a63669e315b6232bd
Modified Files
--------------
src/backend/access/transam/xlogreader.c | 51 +++++++++++++++++++++++++++++++--
src/backend/access/transam/xlogutils.c | 3 ++
src/backend/postmaster/walsummarizer.c | 1 +
src/backend/replication/walsender.c | 3 ++
src/include/access/xlogreader.h | 15 +++++++++-
5 files changed, 70 insertions(+), 3 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Amit Langote | 2026-10-08 03:49:51 | pgsql: Lock RI fast-path rows as of the scan snapshot's command ID |
| Previous Message | Amit Langote | 2026-10-08 03:05:56 | pgsql: Refuse RI fast-path row locks in read-only transactions |