]> git.ipfire.org Git - thirdparty/postgresql.git/commitdiff
Fix wrong variable offset sanity check.
authorPeter Geoghegan <pg@bowt.ie>
Thu, 16 Jul 2026 22:55:35 +0000 (18:55 -0400)
committerPeter Geoghegan <pg@bowt.ie>
Thu, 16 Jul 2026 22:55:35 +0000 (18:55 -0400)
Commit c7aeb775 rewrote the HOT-chain offset sanity checks in three
places, but in heap_get_root_tuples it accidentally tested offnum -- the
outer loop variable, which is already bounded by the loop condition --
instead of nextoffnum, the offset actually passed to PageGetItemId.  The
pre-c7aeb775 check tested nextoffnum.

With the check ineffective, a stale t_ctid could make PageGetItemId read
past the end of the line pointer array (which is data corruption that we
expect to be able to catch here).

Author: Peter Geoghegan <pg@bowt.ie>
Reported-by: Konstantin Knizhnik <knizhnik@garret.ru>
Discussion: https://postgr.es/m/87c7d8a4-3a82-4334-bee6-e8c2ad3f3293@garret.ru
Backpatch-through: 15

src/backend/access/heap/pruneheap.c

index f00c9b81c1a2686d3d683c187d3d6550ff7ae1ea..704187a7268f8458daa752459448b6f82e7c2c25 100644 (file)
@@ -2374,14 +2374,14 @@ heap_get_root_tuples(Page page, OffsetNumber *root_offsets)
                for (;;)
                {
                        /* Sanity check (pure paranoia) */
-                       if (offnum < FirstOffsetNumber)
+                       if (nextoffnum < FirstOffsetNumber)
                                break;
 
                        /*
                         * An offset past the end of page's line pointer array is possible
                         * when the array was truncated
                         */
-                       if (offnum > maxoff)
+                       if (nextoffnum > maxoff)
                                break;
 
                        lp = PageGetItemId(page, nextoffnum);