mirror of
https://github.com/postgres/postgres.git
synced 2025-11-25 12:03:53 +03:00
Install a "dead man switch" to allow the postmaster to detect cases where
a backend has done exit(0) or exit(1) without having disengaged itself from shared memory. We are at risk for this whenever third-party code is loaded into a backend, since such code might not know it's supposed to go through proc_exit() instead. Also, it is reported that under Windows there are ways to externally kill a process that cause the status code returned to the postmaster to be indistinguishable from a voluntary exit (thank you, Microsoft). If this does happen then the system is probably hosed --- for instance, the dead session might still be holding locks. So the best recovery method is to treat this like a backend crash. The dead man switch is armed for a particular child process when it acquires a regular PGPROC, and disarmed when the PGPROC is released; these should be the first and last touches of shared memory resources in a backend, or close enough anyway. This choice means there is no coverage for auxiliary processes, but I doubt we need that, since they shouldn't be executing any user-provided code anyway. This patch also improves the management of the EXEC_BACKEND ShmemBackendArray array a bit, by reducing search costs. Although this problem is of long standing, the lack of field complaints seems to mean it's not critical enough to risk back-patching; at least not till we get some more testing of this mechanism.
This commit is contained in:
@@ -7,7 +7,7 @@
|
||||
* Portions Copyright (c) 1996-2009, PostgreSQL Global Development Group
|
||||
* Portions Copyright (c) 1994, Regents of the University of California
|
||||
*
|
||||
* $PostgreSQL: pgsql/src/include/storage/pmsignal.h,v 1.23 2009/02/23 09:28:50 heikki Exp $
|
||||
* $PostgreSQL: pgsql/src/include/storage/pmsignal.h,v 1.24 2009/05/05 19:59:00 tgl Exp $
|
||||
*
|
||||
*-------------------------------------------------------------------------
|
||||
*/
|
||||
@@ -33,12 +33,20 @@ typedef enum
|
||||
NUM_PMSIGNALS /* Must be last value of enum! */
|
||||
} PMSignalReason;
|
||||
|
||||
/* PMSignalData is an opaque struct, details known only within pmsignal.c */
|
||||
typedef struct PMSignalData PMSignalData;
|
||||
|
||||
/*
|
||||
* prototypes for functions in pmsignal.c
|
||||
*/
|
||||
extern void PMSignalInit(void);
|
||||
extern Size PMSignalShmemSize(void);
|
||||
extern void PMSignalShmemInit(void);
|
||||
extern void SendPostmasterSignal(PMSignalReason reason);
|
||||
extern bool CheckPostmasterSignal(PMSignalReason reason);
|
||||
extern int AssignPostmasterChildSlot(void);
|
||||
extern bool ReleasePostmasterChildSlot(int slot);
|
||||
extern void MarkPostmasterChildActive(void);
|
||||
extern void MarkPostmasterChildInactive(void);
|
||||
extern bool PostmasterIsAlive(bool amDirectChild);
|
||||
|
||||
#endif /* PMSIGNAL_H */
|
||||
|
||||
Reference in New Issue
Block a user