Found by the Phase 1 package benchmark harness (benchmarks/packages/pg/{select,insert_batch}.ts, branch wip/pkg-bench-phase1). Reproduces on main 36420d2e56 (Linux x86-64, PostgreSQL 16, pg 8.23.0 compiled from source — the native binding is gone, so #10330 is about different code).
The first parameterized query segfaults; a plain query on the same connection works:
// npm i pg@8.23.0
import pg from "pg";
const c = new pg.Client({ host: "127.0.0.1", port: 55432, user: "bench", database: "bench" });
console.log("connecting"); await c.connect(); console.log("connected");
const r = await c.query("SELECT 1 AS n"); console.log("plain:", r.rows[0].n);
const r2 = await c.query("SELECT $1::int + 1 AS n", [41]); console.log("param:", r2.rows[0].n);
await c.end(); console.log("end");
|
output |
| node 26.5.1 |
connecting / connected / plain: 1 / param: 42 / end |
| perry (main) |
connecting / connected / plain: 1 / Segmentation fault (exit 139) |
Parameterized queries go through pg's extended protocol (Parse/Bind/Describe/Execute, built by pg-protocol's Writer/serializer into a growing Buffer), which the plain query never touches, so the crash is somewhere in that path. #11335 (grown array written back through its box, which fixed the mysql2 segfault) is already on this main and does not cover it. Both benchmark workloads (pg/select, pg/insert_batch) die the same way.
Found by the Phase 1 package benchmark harness (
benchmarks/packages/pg/{select,insert_batch}.ts, branchwip/pkg-bench-phase1). Reproduces on main36420d2e56(Linux x86-64, PostgreSQL 16, pg 8.23.0 compiled from source — the native binding is gone, so #10330 is about different code).The first parameterized query segfaults; a plain query on the same connection works:
connecting/connected/plain: 1/param: 42/endconnecting/connected/plain: 1/ Segmentation fault (exit 139)Parameterized queries go through pg's extended protocol (
Parse/Bind/Describe/Execute, built bypg-protocol'sWriter/serializerinto a growing Buffer), which the plain query never touches, so the crash is somewhere in that path. #11335 (grown array written back through its box, which fixed the mysql2 segfault) is already on this main and does not cover it. Both benchmark workloads (pg/select,pg/insert_batch) die the same way.