Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ

From: Michael Paquier <michael(at)paquier(dot)xyz>
To: Grigorev Jurij <ju(dot)grigorev(at)ftdata(dot)ru>
Cc: Rahul Yadav <rahul(at)rhyadav(dot)com>, "pgsql-hackers(at)lists(dot)postgresql(dot)org" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: BUG #19599: RestoreBlockImage: the decode cross-checks never bound hole_offset + hole_length against BLCKSZ
Date: 2026-09-30 23:53:40
Message-ID: ar2hA_b1Be7VsZdP@paquier.xyz
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs pgsql-hackers

On Tue, Sep 29, 2026 at 08:37:02AM +0000, Grigorev Jurij wrote:
> Thank you very much for the thorough review and testing -- the
> crash-recovery matrix (pglz/lz4/zstd/off + consistency checking) and
> especially the crafted-record repro with pg_waldump --save-fullpage
> crashing without the patch are super convincing. And thanks for
> confirming the back-patch safety argument.
>
> v2 attached, addressing all your points:

XLogRecordAssemble() in xloginsert.c enforces a size policy already
when a page image needs to be included in a record (REGBUF_STANDARD
case, for both the "lower" and "upper" cases). The argument of a
corrupted record does not stand, a CRC32 check would complain before
we ever reach this path. The hand-made record record argument is also
something I have a hard time to buy, because WAL data is trusted.

So, I don't understand what this patch buys us at all, except more
complexity in the replay path.

There may be an argument for the xlogreader facility, but this relies
on the premise that incorrect WAL records are a thing out there.
Again here comes the CRC check in the record header and the WAL
insertion enforcing already some bounds. This feels like test bloat
to me.
--
Michael

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message David Rowley 2026-10-01 02:22:44 Re: BUG #19672: int8shl/int8shr Undefined Behavior on Out-of-Range Shift Amounts
Previous Message Daniel Gustafsson 2026-09-30 18:24:56 Re: autovacuum: automatically propagate updated parameters

Browse pgsql-hackers by date

  From Date Subject
Next Message Henson Choi 2026-09-30 23:56:32 Re: Row pattern recognition
Previous Message Egor Ivkov 2026-09-30 23:42:26 Re: [PATCH] intXshr, intXshl: return error on shift count out of range