We were doing some fuzzing with an oss-fuzz derivative
(
github.com/stroppy-io/pg-fuzz). The usual crashes are ubsan-only
integer shifts. Yesterday it was a new thing - a cassert
in half-dead page processing (originally found on 17.10):
TRAP: failed Assert("leafblkno == scanblkno"), File: "nbtpage.c", Line: 1949
Note, unlike a similar report from 2024 on the same line, this one does
not need any concurrency.
A sweep was done across REL_16 to REL_19 and master heads:
master 5bd2e236e21b nbtpage.c:1959
REL_19_STABLE bb356f869fa5 nbtpage.c:1979
REL_18_STABLE ccffd34399f5 nbtpage.c:1949
REL_17_STABLE 0165f38d11ec nbtpage.c:1949
REL_16_STABLE 6f2f510845c5 nbtpage.c:1954
Stack trace, reproducer SQL and matrix summary attached. Reproduced on
master and REL_19 with the nbtree-leave-page-half-dead injection point.
The reproducer needs VACUUM (INDEX_CLEANUP ON).
I of course LLMed this and have a patch. LMK if it is of any interest.
Hope it was helpful,
Iliia