Found while validating #11340 on perrymaster (Linux x86_64) against a live PostgreSQL 16.15, using pg 8.23.0 compiled from source.
On current main (e6ad5f3), a parameterised pg query segfaults on the main thread. A query without parameters works.
import pg from "pg";
const c = new pg.Client({ host: "127.0.0.1", port: 45432, user: "perry_trust", password: "x", database: "perry_test" });
await c.connect();
const r1 = await c.query("SELECT 1 + 1 AS two");
console.log("r1", r1.rows[0].two); // prints 2
const r2 = await c.query("SELECT $1::int * 3 AS x", [7]); // SIGSEGV
console.log("r2", r2.rows[0].x);
await c.end();
The build was PERRY_NO_AUTO_OPTIMIZE=1, and it failed in 3 of 3 runs. Backtrace (--debug-symbols):
#0 js_buffer_write_len
#1 perry_runtime::object::buffer_dispatch::dispatch_buffer_method
#2 perry_runtime::object::native_call_method::handle_methods::dispatch_handle
#3 js_native_call_method
#4 js_typed_feedback_native_call_method
#5 js_typed_feedback_native_call_method_by_id
#6 perry_method_…pg_protocol_dist_buffer_writer_js__Writer__addInt32PrefixedString$pshape () at buffer-writer.js:107
#7 perry_closure_…pg_protocol_dist_serializer_js__19 () at serializer.js:83
The crash is in buffer.write(string, offset, 'utf-8') inside the $pshape clone of Writer.addInt32PrefixedString. The same program passed on the older main that #11343 was validated against (fcac18a). With the exact buffer-writer.js copied into a package-free program, Writer does not crash when called directly, so the failure depends on how the clone is specialised under pg. I have not reduced it further.
Found while validating #11340 on perrymaster (Linux x86_64) against a live PostgreSQL 16.15, using pg 8.23.0 compiled from source.
On current main (e6ad5f3), a parameterised pg query segfaults on the main thread. A query without parameters works.
The build was
PERRY_NO_AUTO_OPTIMIZE=1, and it failed in 3 of 3 runs. Backtrace (--debug-symbols):The crash is in
buffer.write(string, offset, 'utf-8')inside the$pshapeclone ofWriter.addInt32PrefixedString. The same program passed on the older main that #11343 was validated against (fcac18a). With the exactbuffer-writer.jscopied into a package-free program,Writerdoes not crash when called directly, so the failure depends on how the clone is specialised under pg. I have not reduced it further.