pgsql: Fix incorrect reinit of run-time pruning for EPQ rechecks

From: David Rowley <drowley(at)postgresql(dot)org>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Fix incorrect reinit of run-time pruning for EPQ rechecks
Date: 2026-10-08 22:04:36
Message-ID: E1xEwE8-00000000s1M-0xLw@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Fix incorrect reinit of run-time pruning for EPQ rechecks

For run-time partition pruning running during execution (rather than at
executor startup), EvalPlanQualStart() reuses the es_part_prune_states
from the parent EState. This could cause an issue when the EPQ recheck is
finished, its EState is cleaned up and the es_query_cxt is deleted by
FreeExecutorState(). That cleanup could free memory that was allocated
again in InitExecPartitionPruneContexts() when it was called for the EPQ's
EState, and naturally, those fields got allocated in the EPQ's
es_query_cxt MemoryContext, which overwrote the ones for the parent
EState. If pruning occurs again after the EPQ's EState was cleaned up,
then we could have accessed free'd memory. This certainly caused issues in
debug builds because we clobber freed memory, but may not have in
production, depending on if the MemoryContext being deleted results in a
free(). It may not if the allocation was on the context's init block and
the context was pushed onto context_freelists[] for reuse.

Here we fix this by adding an "initialized" field to PartitionPruneState
and exit early in InitExecPartitionPruneContexts() when the state is
already initialized.

This was broken by bb3ec16e1, but the breakage there is slightly
different as that commit neglected to do what was fixed in 8741e48e5
(which did get backpatched to v18 in 9a82a64ed).

Reported-by: Vladimir Savin <vladimir(at)encord(dot)com>
Author: David Rowley <dgrowleyml(at)gmail(dot)com>
Reviewed-by: Andrey Rachitskiy <pl0h0yp1(at)gmail(dot)com>
Discussion: https://postgr.es/m/CAP2G_gGpV=rKMLuET4RW-qO41GvBvi6Czsjsj16eT9hAwHxG6w@mail.gmail.com
Backpatch-through: 18

Branch
------
REL_18_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c7328770ba50f6250930cb023effe3354c49de32

Modified Files
--------------
src/backend/executor/execPartition.c | 12 ++++++
src/include/executor/execPartition.h | 3 ++
.../expected/eval-plan-qual-partition-prune.out | 30 +++++++++++++++
src/test/isolation/isolation_schedule | 1 +
.../specs/eval-plan-qual-partition-prune.spec | 43 ++++++++++++++++++++++
5 files changed, 89 insertions(+)

Browse pgsql-committers by date

  From Date Subject
Next Message Michael Paquier 2026-10-09 05:00:18 pgsql: Treat any negative ws_file as closed in xlogreader.c
Previous Message David Rowley 2026-10-08 22:04:15 pgsql: Fix incorrect reinit of run-time pruning for EPQ rechecks