Fix possible crash when RI fast-path metadata is invalidated mid-check ri_FastPathCheck() read riinfo->fpmeta again after ri_CheckFunctionPermissions(), which looks up catalog entries and so can process invalidation messages. If one of them reaches InvalidateConstraintCacheCallBack() for the constraint, as a pg_amop change or a cache reset would, the callback detaches the metadata and sets riinfo->fpmeta to NULL, which build_index_scankeys() then dereferences.
The callback already defers freeing detached metadata until AtEOXact_RI(), and its comment assumes callers keep their own pointer to it, so use a local pointer instead of riinfo->fpmeta. There is no test, as hitting this needs an invalidation to arrive during those catalog lookups. Discussion: https://postgr.es/m/CA+HiwqFaipkMsZ8XP-9sMk21h0Q7rih=npjqxsbaad39vtn...@mail.gmail.com Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/e73e0196d30198e4579656881497f057788bb53d Modified Files -------------- src/backend/utils/adt/ri_triggers.c | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-)
