]> git.ipfire.org Git - thirdparty/postgresql.git/commitdiff
Fix wrong variable offset sanity check.
authorPeter Geoghegan <pg@bowt.ie>
Thu, 16 Jul 2026 22:55:36 +0000 (18:55 -0400)
committerPeter Geoghegan <pg@bowt.ie>
Thu, 16 Jul 2026 22:55:36 +0000 (18:55 -0400)
Commit c7aeb775 rewrote the HOT-chain offset sanity checks in three
places, but in heap_get_root_tuples it accidentally tested offnum -- the
outer loop variable, which is already bounded by the loop condition --
instead of nextoffnum, the offset actually passed to PageGetItemId.  The
pre-c7aeb775 check tested nextoffnum.

With the check ineffective, a stale t_ctid could make PageGetItemId read
past the end of the line pointer array (which is data corruption that we
expect to be able to catch here).

Author: Peter Geoghegan <pg@bowt.ie>
Reported-by: Konstantin Knizhnik <knizhnik@garret.ru>
Discussion: https://postgr.es/m/87c7d8a4-3a82-4334-bee6-e8c2ad3f3293@garret.ru
Backpatch-through: 15

src/backend/access/heap/pruneheap.c

index 85cdceb0524812e08da416b51316b0c0554e24b3..b146119d7aff3beb5bc0f1725fb1bf6ca9f7a457 100644 (file)
@@ -2374,14 +2374,14 @@ heap_get_root_tuples(Page page, OffsetNumber *root_offsets)
                for (;;)
                {
                        /* Sanity check (pure paranoia) */
-                       if (offnum < FirstOffsetNumber)
+                       if (nextoffnum < FirstOffsetNumber)
                                break;
 
                        /*
                         * An offset past the end of page's line pointer array is possible
                         * when the array was truncated
                         */
-                       if (offnum > maxoff)
+                       if (nextoffnum > maxoff)
                                break;
 
                        lp = PageGetItemId(page, nextoffnum);