Handle interleavings between CREATE DATABASE steps and base backup.
authorNoah Misch <noah@leadboat.com>
Thu, 1 Feb 2024 21:44:19 +0000 (13:44 -0800)
committerNoah Misch <noah@leadboat.com>
Thu, 1 Feb 2024 21:44:22 +0000 (13:44 -0800)
commitd493bed28f7f6c77051bba3dde383e0ff78d3a19
tree01a85c8561df4442276f562075b493234e85273e
parent970b1aeeba78ad609455f7b55c9d81d06f2a75a5
Handle interleavings between CREATE DATABASE steps and base backup.

Restoring a base backup taken in the middle of CreateDirAndVersionFile()
or write_relmap_file() would lose the function's effects.  The symptom
was absence of the database directory, PG_VERSION file, or
pg_filenode.map.  If missing the directory, recovery would fail.  Either
missing file would not fail recovery but would render the new database
unusable.  Fix CreateDirAndVersionFile() with the transam/README "action
first and then write a WAL entry" strategy.  That has a side benefit of
moving filesystem mutations out of a critical section, reducing the ways
to PANIC.  Fix the write_relmap_file() call with a lock acquisition, so
it interacts with checkpoints like non-CREATE DATABASE calls do.
Back-patch to v15, where commit 9c08aea6a3090a396be334cc58c511edab05776a
introduced STRATEGY=WAL_LOG and made it the default.

Discussion: https://postgr.es/m/20240130195003.0a.nmisch@google.com
src/backend/commands/dbcommands.c
src/backend/utils/cache/relmapper.c