Home / Companies / ClickHouse / Blog / Post Details
Content Deep Dive

Memory safety for Postgres extensions in C/C++

Blog post from ClickHouse

Post Details
Company
Date Published
Author
-
Word Count
833
Company Posts That Month
39
Language
English
Hacker News Points
-
Post removed?
No
Summary

ClickHouse’s PostgreSQL extensions have required careful integration of C++ components into PostgreSQL’s C-based runtime, whose MemoryContext allocation model and setjmp/longjmp error handling are incompatible with C++ destructors and exceptions. The post explains that PostgreSQL errors can bypass C++ cleanup, while uncaught C++ exceptions can abort backend processes and potentially trigger cluster-wide recovery. Each extension adopts a different containment strategy: pg_clickhouse eliminated C++ by replacing its dependency with C libraries, pg_re2 confines C++ allocations and logic to a wrapper that never calls PostgreSQL code, pg_chdb runs its C++ ClickHouse engine in a separate helper process, and pg_stat_ch isolates C++ within a background worker while adding exception and termination handling. Although these measures reduce risk, the discussion notes that worker-level safeguards cannot fully guarantee crash isolation or shared-memory safety, and describes fixes for ownership bugs plus ongoing work to move pg_stat_ch’s C++ dependencies toward stronger process separation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
OpenTelemetry 1 125 18 15 -83%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.