Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit260dbf1

Browse files
committed
Fix oversight in handling of modifiedCols sincef245236
Commitf245236 fixed a memory leak by moving the modifiedCols bitmapinto the per-row memory context. In the case of AFTER UPDATE triggers,the bitmap is however referenced from an event kept until the end of thequery, resulting in a use-after-free bug.Fixed by copying the bitmap into the AfterTriggerEvents memory context,which is the one where we keep the trigger events. There's only oneplace that needs to do the copy, but the memory context may not existyet. Doing that in a separate function seems more readable.Report by Alexander Pyhalov, fix by me. Backpatch to 13, where thebitmap was added to the event by commit71d60e2.Reported-by: Alexander PyhalovBackpatch-through: 13Discussion:https://postgr.es/m/acddb17c89b0d6cb940eaeda18c08bbe@postgrespro.ru
1 parentc1affa3 commit260dbf1

File tree

1 file changed

+32
-1
lines changed

1 file changed

+32
-1
lines changed

‎src/backend/commands/trigger.c

Lines changed: 32 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3689,6 +3689,37 @@ afterTriggerCheckState(AfterTriggerShared evtshared)
36893689
return ((evtshared->ats_event&AFTER_TRIGGER_INITDEFERRED)!=0);
36903690
}
36913691

3692+
/* ----------
3693+
* afterTriggerCopyBitmap()
3694+
*
3695+
* Copy bitmap into AfterTriggerEvents memory context, which is where the after
3696+
* trigger events are kept.
3697+
* ----------
3698+
*/
3699+
staticBitmapset*
3700+
afterTriggerCopyBitmap(Bitmapset*src)
3701+
{
3702+
Bitmapset*dst;
3703+
MemoryContextoldcxt;
3704+
3705+
if (src==NULL)
3706+
returnNULL;
3707+
3708+
/* Create event context if we didn't already */
3709+
if (afterTriggers.event_cxt==NULL)
3710+
afterTriggers.event_cxt=
3711+
AllocSetContextCreate(TopTransactionContext,
3712+
"AfterTriggerEvents",
3713+
ALLOCSET_DEFAULT_SIZES);
3714+
3715+
oldcxt=MemoryContextSwitchTo(afterTriggers.event_cxt);
3716+
3717+
dst=bms_copy(src);
3718+
3719+
MemoryContextSwitchTo(oldcxt);
3720+
3721+
returndst;
3722+
}
36923723

36933724
/* ----------
36943725
* afterTriggerAddEvent()
@@ -5806,7 +5837,7 @@ AfterTriggerSaveEvent(EState *estate, ResultRelInfo *relinfo,
58065837
new_shared.ats_table=transition_capture->tcs_private;
58075838
else
58085839
new_shared.ats_table=NULL;
5809-
new_shared.ats_modifiedcols=modifiedCols;
5840+
new_shared.ats_modifiedcols=afterTriggerCopyBitmap(modifiedCols);
58105841

58115842
afterTriggerAddEvent(&afterTriggers.query_stack[afterTriggers.query_depth].events,
58125843
&new_event,&new_shared);

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp