forked frompostgres/postgres
- Notifications
You must be signed in to change notification settings - Fork6
Commit8e5eef5
committed
Fix dereference of dangling pointer in GiST index buffering build.
gistBuildCallback tried to fetch the size of an index tuple thatmight have already been freed by gistProcessEmptyingQueue.While this seems to usually be harmless in production builds,in principle it could result in a SIGSEGV, or more likely a bogusvalue for indtuplesSize leading to poor page-split decisions laterin the build.The memory management here is confusing and could stand to berefactored, but for the moment it seems to be enough to fetchthe tuple size sooner. AFAICT the indtuples[Size] totals aren'tused in between these places; even if they were, the updatedvalues shouldn't be any worse to use. So just move theincrementing of the totals up.It's not very clear why our valgrind-using buildfarm animalshaven't noticed this problem, because the relevant code pathdoes seem to be exercised according to the code coverage report.I think the reason that we didn't fix this bug after the firstreport is that I'd wanted to try to understand that better.However, now that it's been re-discovered let's just be pragmaticand fix it already.Original report by Alexander Lakhin (bug #16329),later rediscovered by Egor Chindyaskin (bug #17874).Patch by Alexander Lakhin (commentary by Pavel Borisov and me).Back-patch to all supported branches.Discussion:https://postgr.es/m/16329-7a6aa9b6fa1118a1@postgresql.orgDiscussion:https://postgr.es/m/17874-63ca6c7ce42d2103@postgresql.org1 parent3aa9613 commit8e5eef5
1 file changed
+13
-4
lines changedLines changed: 13 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
901 | 901 |
| |
902 | 902 |
| |
903 | 903 |
| |
| 904 | + | |
| 905 | + | |
| 906 | + | |
| 907 | + | |
| 908 | + | |
| 909 | + | |
| 910 | + | |
| 911 | + | |
| 912 | + | |
| 913 | + | |
| 914 | + | |
| 915 | + | |
| 916 | + | |
904 | 917 |
| |
905 | 918 |
| |
906 | 919 |
| |
| |||
916 | 929 |
| |
917 | 930 |
| |
918 | 931 |
| |
919 |
| - | |
920 |
| - | |
921 |
| - | |
922 |
| - | |
923 | 932 |
| |
924 | 933 |
| |
925 | 934 |
| |
|
0 commit comments
Comments
(0)