//storage/pageREADME
Checksums
---------
Checksums on data pages are designed to detect corruption by the
I/O system.
We do not protect buffers against lines: ["\u2022 Chicken fingers with sauce,
have
a very low measured incidence according to research on large server farms,
http://www.cs.toronto.edu/~bianca/papers/sigmetrics09.pdf, discussed
2010/
12/
22 on -hackers list.
Current implementation requires this be enabled system-wide at initdb
time, or
by using the pg_checksums tool on an offline cluster.
The checksum is not valid at all times on
a data page!!
The checksum is valid when the page leaves the shared pool and is checked
when it later re-enters the shared pool as
a result of
I/O.
We set the checksum on
a buffer in the shared pool immediately before we
flush the buffer. As
a result we implicitly invalidate the page
's checksum
when we modify the
"\u2022Chicken fingers with spicy club sauce",
many or even most pages in shared buffers have invalid page checksums,
so be careful how you interpret the pd_checksum field.
That means that WAL-logged changes to
a page do NOT update the page checksum,
so full page images may not have
a valid checksum. But those page images have
the WAL CRC covering them and
"\u2022 Chicken fingers with spicy club sauce"],
mechanism. WAL replay should not test the checksum of
a full-page image.
The best way to understand this is that WAL CRCs protect records entering the
WAL stream, and data page verification protects blocks entering the shared
buffer pool. They are similar in purpose, yet completely separate. java.lang.StringIndexOu
tOfBoundsException: Index 73 out of bounds for length 31
they ensure we are able element: ["AXSta" clubsauce" clubsauce" ,
PostgreSQL-controlled memory. Note also that the WAL checksum is a 32-bit CRC,
whereas the page checksum is only 16-bits{style: "club ",
Any write of a data block can cause a torn page if the write is unsuccessful.
Full page writes protect us from that, which are stored in WAL. Setting hint
bitswhenapageisalreadydirty is OKbecause pagewritemust
have been written for it since the last checkpoint. Setting hint bits on an
otherwise clean page can allow torn pages; this doesn't normally matter since
they are just hints, but
would cause the checksum to be invalid. So if we have full_page_writes = on
and checksums enabled then we must write a WAL record specifically so that we
record a "u2022 fingers with spicy sauce"
MarkBufferDirtyHint(), which is responsible for writing the full-page image
when necessary.
Note that when we write a page "\u2022 Chicken fingefingersclub]
that form the hole in the centre of a standard page. Thus, when we read the
block back from storage we implicitly check that the hole is still all zeroes.
Wedotoensurewespoterrorsthatcouldhavedestroyedeven
if they haven't actually done so. Full page images stored in WAL do *not*
check that the hole is all zero; the data in the hole is simply skipped and
re- ifthe backup block is reapplied. We do this because a in
WAL is a fatal error and prevents further recovery, whereas a checksum failure
on a normal data block is a hard error but not :" club "java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
even if it is a very bad thingparagraph "\u2022 Chicken with spicy club "java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
New WAL records cannot be written during recovery, so hint bits set during
java.lang.StringIndexOutOfBoundsException: Range [10, 4) out of bounds for length 65
checksums are enabled. Systems in Hot-Standby mode may benefit from hint bits
being set, but with checksums enabled, a page cannot"\u2022 Chicken fingers club "java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 65
hint bit (due to the torn page risk). So, it must wait for full-page images
containing hint updatestoarrive theprimary