Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Skip to content

Commit 71d02dc

Browse files
author
Richard Guo
committed
Fix unsafe access to BufferDescriptors
When considering a local buffer, the GetBufferDescriptor() call in BufferGetLSNAtomic() would be retrieving a shared buffer with a bad buffer ID. Since the code checks whether the buffer is shared before using the retrieved BufferDesc, this issue did not lead to any malfunction. Nonetheless this seems like trouble waiting to happen, so fix it by ensuring that GetBufferDescriptor() is only called when we know the buffer is shared. Author: Tender Wang <tndrwang@gmail.com> Reviewed-by: Xuneng Zhou <xunengzhou@gmail.com> Reviewed-by: Richard Guo <guofenglinux@gmail.com> Discussion: https://postgr.es/m/CAHewXNku-o46-9cmUgyv6LkSZ25doDrWq32p=oz9kfD8ovVJMg@mail.gmail.com Backpatch-through: 13
1 parent c39392e commit 71d02dc

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

src/backend/storage/buffer/bufmgr.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3981,8 +3981,8 @@ BufferIsPermanent(Buffer buffer)
39813981
XLogRecPtr
39823982
BufferGetLSNAtomic(Buffer buffer)
39833983
{
3984-
BufferDesc *bufHdr = GetBufferDescriptor(buffer - 1);
39853984
char *page = BufferGetPage(buffer);
3985+
BufferDesc *bufHdr;
39863986
XLogRecPtr lsn;
39873987
uint32 buf_state;
39883988

@@ -3996,6 +3996,7 @@ BufferGetLSNAtomic(Buffer buffer)
39963996
Assert(BufferIsValid(buffer));
39973997
Assert(BufferIsPinned(buffer));
39983998

3999+
bufHdr = GetBufferDescriptor(buffer - 1);
39994000
buf_state = LockBufHdr(bufHdr);
40004001
lsn = PageGetLSN(page);
40014002
UnlockBufHdr(bufHdr, buf_state);

0 commit comments

Comments
 (0)