RE: [PATCH] Fix TOCTOU race in ReplicationSlotsComputeRequiredLSN()

From: "Zhijie Hou (Fujitsu)" <houzj(dot)fnst(at)fujitsu(dot)com>
To: JoongHyuk Shin <sjh910805(at)gmail(dot)com>
Cc: "pgsql-hackers(at)lists(dot)postgresql(dot)org" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: RE: [PATCH] Fix TOCTOU race in ReplicationSlotsComputeRequiredLSN()
Date: 2026-04-17 06:59:14
Message-ID: TYRPR01MB14195CA431CFC783F77FB8AEF94202@TYRPR01MB14195.jpnprd01.prod.outlook.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Friday, April 17, 2026 2:50 PM JoongHyuk Shin <sjh910805(at)gmail(dot)com> wrote:
> Commit 2a5225b99d7 fixed a race in ReplicationSlotsComputeRequiredXmin()
> where ReplicationSlotControlLock was released before the global xmin
> update, allowing a concurrent backend to overwrite a correct value with
> a stale one.
>
> ReplicationSlotsComputeRequiredLSN() has the same problem,
> it releases the lock before calling XLogSetReplicationSlotMinimumLSN(),
> so a stale minimum LSN can overwrite a correct (lower) one,
> potentially leading to premature WAL removal.
>
> The attached patch moves LWLockRelease() to after the LSN update,
> matching the xmin fix.
> Since 2a5225b99d7 was backpatched to all supported versions,
> I believe this should be as well.

Thanks for noticing this. There is an existing thread [1] that I started
following 2a5225b99d7 to address the same issue. The patch you posted
only increases the lock scope in ReplicationSlotsComputeRequiredLSN() but does
not increase the lock level when reserving WALs, so I think it would not
fix the issue.

Please feel free to review the patch in that thread if you find it helpful.

[1] https://commitfest.postgresql.org/patch/6451/

Best Regards,
Hou zj

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Amit Kapila 2026-04-17 07:19:36 Re: Fix stats reporting delays in logical parallel apply worker
Previous Message JoongHyuk Shin 2026-04-17 06:50:01 [PATCH] Fix TOCTOU race in ReplicationSlotsComputeRequiredLSN()