Commit
c7aeb775 rewrote the HOT-chain offset sanity checks in three
places, but in heap_get_root_tuples it accidentally tested offnum -- the
outer loop variable, which is already bounded by the loop condition --
instead of nextoffnum, the offset actually passed to PageGetItemId. The
pre-
c7aeb775 check tested nextoffnum.
With the check ineffective, a stale t_ctid could make PageGetItemId read
past the end of the line pointer array (which is data corruption that we
expect to be able to catch here).
Author: Peter Geoghegan <pg@bowt.ie>
Reported-by: Konstantin Knizhnik <knizhnik@garret.ru>
Discussion: https://postgr.es/m/
87c7d8a4-3a82-4334-bee6-
e8c2ad3f3293@garret.ru
Backpatch-through: 15
for (;;)
{
/* Sanity check (pure paranoia) */
- if (offnum < FirstOffsetNumber)
+ if (nextoffnum < FirstOffsetNumber)
break;
/*
* An offset past the end of page's line pointer array is possible
* when the array was truncated
*/
- if (offnum > maxoff)
+ if (nextoffnum > maxoff)
break;
lp = PageGetItemId(page, nextoffnum);