forked frompostgres/postgres
- Notifications
You must be signed in to change notification settings - Fork6
Commite629846
committed
Fix incorrect accessing of pfree'd memory in Memoize
For pass-by-reference types, the code added in0b053e7, which aimed toresolve a memory leak, was overly aggressive in resetting the per-tuplememory context which could result in pfree'd memory being accessedresulting in failing to find previously cached results in the hashtable.What was happening was prepare_probe_slot() was switching to theper-tuple memory context and calling ExecEvalExpr(). ExecEvalExpr() mayhave required a memory allocation. Both MemoizeHash_hash() andMemoizeHash_equal() were aggressively resetting the per-tuple contextand after determining the hash value, the context would have gotten resetbefore MemoizeHash_equal() was called. This could have resulted inMemoizeHash_equal() looking at pfree'd memory.This is less likely to have caused issues on a production build as someother allocation would have had to have reused the pfree'd memory tooverwrite it. Otherwise, the original contents would have been intact.However, this clearly caused issues on MEMORY_CONTEXT_CHECKING builds.Author: Tender Wang, Andrei LepikhovReported-by: Tender Wang (using SQLancer)Reviewed-by: Andrei Lepikhov, Richard Guo, David RowleyDiscussion:https://postgr.es/m/CAHewXNnT6N6UJkya0z-jLFzVxcwGfeRQSfhiwA+NyLg-x8iGew@mail.gmail.comBackpatch-through: 14, where Memoize was added1 parent21e3a8b commite629846
File tree
3 files changed
+63
-6
lines changed- src
- backend/executor
- test/regress
- expected
- sql
3 files changed
+63
-6
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
207 | 207 | | |
208 | 208 | | |
209 | 209 | | |
210 | | - | |
211 | 210 | | |
212 | 211 | | |
213 | 212 | | |
| |||
265 | 264 | | |
266 | 265 | | |
267 | 266 | | |
268 | | - | |
269 | 267 | | |
270 | 268 | | |
271 | 269 | | |
272 | 270 | | |
273 | 271 | | |
274 | 272 | | |
275 | 273 | | |
276 | | - | |
| 274 | + | |
277 | 275 | | |
278 | 276 | | |
279 | 277 | | |
| |||
699 | 697 | | |
700 | 698 | | |
701 | 699 | | |
| 700 | + | |
702 | 701 | | |
703 | 702 | | |
704 | 703 | | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
| 707 | + | |
| 708 | + | |
| 709 | + | |
| 710 | + | |
| 711 | + | |
705 | 712 | | |
706 | 713 | | |
707 | 714 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
129 | 129 | | |
130 | 130 | | |
131 | 131 | | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
132 | 162 | | |
133 | 163 | | |
134 | 164 | | |
135 | | - | |
136 | 165 | | |
137 | 166 | | |
138 | 167 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
77 | 99 | | |
78 | 100 | | |
79 | 101 | | |
80 | | - | |
81 | 102 | | |
82 | 103 | | |
83 | 104 | | |
| |||
0 commit comments
Comments
(0)