> 07.04.2026 00:58, Nathan Bossart wrote:
> > Committed after some more editorialization.
>
> Please look at a new anomaly, I and SQLsmith have discovered:
> SELECT (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1),
>      (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1);
> ERROR:  detected double pfree in PgStat Snapshot 0x5f6fa4d95d50

oops, nice catch!

With the default stats_fetch_consistency setting of
PGSTAT_FETCH_CONSISTENCY_CACHE,
the stats returned by pgstat_fetch_entry() are allocated in the
snapshot's memory context,
so they get free'd when the snapshot is cleared by pgstat_clear_snapshot().
That means inside relation_needs_vacanalyze() we should only
pfree(tabentry) when
pgstat_fetch_consistency is PGSTAT_FETCH_CONSISTENCY_NONE,
as in that mode the stats are palloc'd in the caller's memory context
and must be freed explicitly.

autovacuum.c forces pgstat_fetch_consistency to PGSTAT_FETCH_CONSISTENCY_NONE
for the autovacuum launcher, so the pfree() was never an issue there.
I don't think we should do the same for pg_stat_get_autovacuum_scores
, as we should
not override the users intentions for fetch consistency, and also it
would complicate the
view greatly as we must force a _NONE consistency and a PG_TRY/PG_CATCH
to restore the original mode.

Attached is the fix:

postgres=# set stats_fetch_consistency = NONE;
SET
postgres=# SELECT (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1),
     (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1);
  score  |  score
---------+---------
 8.5e-08 | 8.5e-08
(1 row)

postgres=# set stats_fetch_consistency = snapshot;
SET
postgres=# SELECT (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1),
     (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1);
  score  |  score
---------+---------
 8.5e-08 | 8.5e-08
(1 row)

postgres=# set stats_fetch_consistency = cache;
SET
postgres=# SELECT (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1),
     (SELECT score FROM pg_stat_get_autovacuum_scores() LIMIT 1);
  score  |  score
---------+---------
 8.5e-08 | 8.5e-08
(1 row)

Attachment: v1-0001-Fix-double-free-in-relation_needs_vacanalyze.patch
Description: Binary data

Reply via email to