Memory safety for Postgres extensions in C/C++
Blog post from ClickHouse
ClickHouse’s PostgreSQL extensions have required careful integration of C++ components into PostgreSQL’s C-based runtime, whose MemoryContext allocation model and setjmp/longjmp error handling are incompatible with C++ destructors and exceptions. The post explains that PostgreSQL errors can bypass C++ cleanup, while uncaught C++ exceptions can abort backend processes and potentially trigger cluster-wide recovery. Each extension adopts a different containment strategy: pg_clickhouse eliminated C++ by replacing its dependency with C libraries, pg_re2 confines C++ allocations and logic to a wrapper that never calls PostgreSQL code, pg_chdb runs its C++ ClickHouse engine in a separate helper process, and pg_stat_ch isolates C++ within a background worker while adding exception and termination handling. Although these measures reduce risk, the discussion notes that worker-level safeguards cannot fully guarantee crash isolation or shared-memory safety, and describes fixes for ownership bugs plus ongoing work to move pg_stat_ch’s C++ dependencies toward stronger process separation.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| OpenTelemetry | 1 | 125 | 18 | 15 | -83% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.