Skip to content

Commit 1e85076

Browse files
committed
PG-1895 Rewrite global providers during basebackup
Before this commit, we excluded 1664_providers from being rewritten during a backup, since this is one of the files that the user has to copy to the destination before the backup starts. It was done so the user can have different global providers and keys to encrypt backup's WAL than the source server. However, this raised several issues in case the server creates new providers or modifies existing ones during the backup. Then, those changes will be lost in the backup and data related to such providers might become unreadable, or redo might struggle to perform a rotation. This commit treats 1664_providers as the rest of the files and makes provider changes safe during the backup. We still don't rewrite wal_keys, as we generate a unique WAL key for the backup, and the server can't generate new WAL keys can't during the backup. Fixes PG-1895
1 parent 72e3b59 commit 1e85076

1 file changed

Lines changed: 9 additions & 10 deletions

File tree

‎src/bin/pg_basebackup/bbstreamer_file.c‎

Lines changed: 9 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -247,19 +247,18 @@ bbstreamer_extractor_content(bbstreamer *streamer, bbstreamer_member *member,
247247
#ifdef PERCONA_EXT
248248
/*
249249
* A streamed WAL is encrypted with the newly generated WAL key,
250-
* hence we have to prevent these files from rewriting.
250+
* hence we have to prevent wal_keys from rewriting.
251251
*/
252-
if (mystreamer->encryped_wal)
252+
if (strcmp(member->pathname, "pg_tde/wal_keys") == 0)
253253
{
254-
if (strcmp(member->pathname, "pg_tde/wal_keys") == 0 ||
255-
strcmp(member->pathname, "pg_tde/1664_providers") == 0)
254+
if (mystreamer->encryped_wal)
256255
break;
257-
}
258-
else if (strcmp(member->pathname, "pg_tde/wal_keys") == 0)
259-
{
260-
pg_log_warning("the source has WAL keys, but no WAL encryption configured for the target backups");
261-
pg_log_warning_detail("This may lead to exposed data and broken backup.");
262-
pg_log_warning_hint("Run pg_basebackup with -E to encrypt streamed WAL.");
256+
else
257+
{
258+
pg_log_warning("the source has WAL keys, but no WAL encryption configured for the target backups");
259+
pg_log_warning_detail("This may lead to exposed data and broken backup.");
260+
pg_log_warning_hint("Run pg_basebackup with -E to encrypt streamed WAL.");
261+
}
263262
}
264263
#endif
265264
mystreamer->file =

0 commit comments

Comments
 (0)