Skip to content

pg 8.23.0 (compiled from source): first parameterized query segfaults; plain queries work #11459

Description

@proggeramlug

Found by the Phase 1 package benchmark harness (benchmarks/packages/pg/{select,insert_batch}.ts, branch wip/pkg-bench-phase1). Reproduces on main 36420d2e56 (Linux x86-64, PostgreSQL 16, pg 8.23.0 compiled from source — the native binding is gone, so #10330 is about different code).

The first parameterized query segfaults; a plain query on the same connection works:

// npm i pg@8.23.0
import pg from "pg";
const c = new pg.Client({ host: "127.0.0.1", port: 55432, user: "bench", database: "bench" });
console.log("connecting"); await c.connect(); console.log("connected");
const r = await c.query("SELECT 1 AS n"); console.log("plain:", r.rows[0].n);
const r2 = await c.query("SELECT $1::int + 1 AS n", [41]); console.log("param:", r2.rows[0].n);
await c.end(); console.log("end");
output
node 26.5.1 connecting / connected / plain: 1 / param: 42 / end
perry (main) connecting / connected / plain: 1 / Segmentation fault (exit 139)

Parameterized queries go through pg's extended protocol (Parse/Bind/Describe/Execute, built by pg-protocol's Writer/serializer into a growing Buffer), which the plain query never touches, so the crash is somewhere in that path. #11335 (grown array written back through its box, which fixed the mysql2 segfault) is already on this main and does not cover it. Both benchmark workloads (pg/select, pg/insert_batch) die the same way.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions