pgsql: Fix dereference of dangling pointer in GiST index buffering buil

Поиск
Список
Период
Сортировка
От Tom Lane
Тема pgsql: Fix dereference of dangling pointer in GiST index buffering buil
Дата
Msg-id E1phXm2-000KWx-Sa@gemulon.postgresql.org
обсуждение исходный текст
Список pgsql-committers
Fix dereference of dangling pointer in GiST index buffering build.

gistBuildCallback tried to fetch the size of an index tuple that
might have already been freed by gistProcessEmptyingQueue.
While this seems to usually be harmless in production builds,
in principle it could result in a SIGSEGV, or more likely a bogus
value for indtuplesSize leading to poor page-split decisions later
in the build.

The memory management here is confusing and could stand to be
refactored, but for the moment it seems to be enough to fetch
the tuple size sooner.  AFAICT the indtuples[Size] totals aren't
used in between these places; even if they were, the updated
values shouldn't be any worse to use.  So just move the
incrementing of the totals up.

It's not very clear why our valgrind-using buildfarm animals
haven't noticed this problem, because the relevant code path
does seem to be exercised according to the code coverage report.
I think the reason that we didn't fix this bug after the first
report is that I'd wanted to try to understand that better.
However, now that it's been re-discovered let's just be pragmatic
and fix it already.

Original report by Alexander Lakhin (bug #16329),
later rediscovered by Egor Chindyaskin (bug #17874).

Patch by Alexander Lakhin (commentary by Pavel Borisov and me).
Back-patch to all supported branches.

Discussion: https://postgr.es/m/16329-7a6aa9b6fa1118a1@postgresql.org
Discussion: https://postgr.es/m/17874-63ca6c7ce42d2103@postgresql.org

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/8e5eef50c5b41fd39ad60365c9c1b46782f881ca

Modified Files
--------------
src/backend/access/gist/gistbuild.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)


В списке pgsql-committers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: pgsql: Add missing .gitignore entries.
Следующее
От: Daniel Gustafsson
Дата:
Сообщение: pgsql: Support connection load balancing in libpq