Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commitcb3d674

Browse files
committed
Fix race in dsm_attach() when handles are reused.
DSM handle values can be reused as soon as the underlying shared memoryobject has been destroyed. That means that for a brief moment wemight have two DSM slots with the same handle. While trying to attach,if we encounter a slot with refcnt == 1, meaning that it is currentlybeing destroyed, we should continue our search in case the same handleexists in another slot.The race manifested as a rare "dsa_area could not attach to segment"error, and was more likely in 10 and 11 due to the lack of distinctseed for random() in parallel workers. It was made very unlikely inin master by commit197e4af, and older releases don't usually createnew DSM segments in background workers so it was also unlikely there.This fixes the root cause of bug report #15585, in which the errorcould also sometimes result in a self-deadlock in the error path.It's not yet clear if further changes are needed to avoid that failuremode.Back-patch to 9.4, where dsm.c arrived.Author: Thomas MunroReported-by: Justin Pryzby, Sergei KornilovDiscussion:https://postgr.es/m/20190207014719.GJ29720@telsasoft.comDiscussion:https://postgr.es/m/15585-324ff6a93a18da46@postgresql.org
1 parent2cfdf24 commitcb3d674

File tree

1 file changed

+8
-10
lines changed
  • src/backend/storage/ipc

1 file changed

+8
-10
lines changed

‎src/backend/storage/ipc/dsm.c

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -597,22 +597,20 @@ dsm_attach(dsm_handle h)
597597
nitems=dsm_control->nitems;
598598
for (i=0;i<nitems;++i)
599599
{
600-
/* If the reference count is 0, the slot is actually unused. */
601-
if (dsm_control->item[i].refcnt==0)
600+
/*
601+
* If the reference count is 0, the slot is actually unused. If the
602+
* reference count is 1, the slot is still in use, but the segment is
603+
* in the process of going away; even if the handle matches, another
604+
* slot may already have started using the same handle value by
605+
* coincidence so we have to keep searching.
606+
*/
607+
if (dsm_control->item[i].refcnt <=1)
602608
continue;
603609

604610
/* If the handle doesn't match, it's not the slot we want. */
605611
if (dsm_control->item[i].handle!=seg->handle)
606612
continue;
607613

608-
/*
609-
* If the reference count is 1, the slot is still in use, but the
610-
* segment is in the process of going away. Treat that as if we
611-
* didn't find a match.
612-
*/
613-
if (dsm_control->item[i].refcnt==1)
614-
break;
615-
616614
/* Otherwise we've found a match. */
617615
dsm_control->item[i].refcnt++;
618616
seg->control_slot=i;

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp