↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

DocumentationVersion comparison

POSTGRESQL · VERSION COMPARE

PostgreSQL 10.1 release changes

All features, fixes, and compatibility notes in this release, with related records from other versions.

All changes in this release
All changes in this release

Includes changes after the source version through the target. A major version name means its initial release.

From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.

Complete release changes

10.1

2017-11-09

Export JSON
37changesFeatures, fixes, improvements
1releaseGrouped by release
3CVEsVulnerability IDs mentioned in these notes

10.1 HistoricalSupport ends 2022-11-10

Security records mentioned in this release 3 CVEs
CVEs mentioned in these notes, including possible follow-up fixes for earlier vulnerabilities
CVE / issueSeverityFixed version
CVE-2017-12172

Fix sample server-start scripts to become $PGUSER before opening $PGLOG

8.410.1
CVE-2017-15098

Fix crash due to rowtype mismatch in json{b}_populate_recordset()

4.310.1
CVE-2017-15099

Ensure that INSERT ... ON CONFLICT DO UPDATE checks table permissions and RLS policies in all cases

3.110.1

PostgreSQL 10.1

Migration and compatibility

A dump/restore is not required for those running 10.X.

However, if you use BRIN indexes, see the fourth changelog entry below.

SecurityEnsure that INSERT ... ON CONFLICT DO UPDATE checks table permissions and RLS policies in all cases

Changes

Ensure that INSERT ... ON CONFLICT DO UPDATE checks table permissions and RLS policies in all cases (Dean Rasheed)

The update path of INSERT ... ON CONFLICT DO UPDATE requires SELECT permission on the columns of the arbiter index, but it failed to check for that in the case of an arbiter specified by constraint name. In addition, for a table with row level security enabled, it failed to check updated rows against the table's SELECT policies (regardless of how the arbiter index was specified). (CVE-2017-15099)

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

SecurityFix crash due to rowtype mismatch in json{b}_populate_recordset()

Changes

Fix crash due to rowtype mismatch in json{b}_populate_recordset() (Michael Paquier, Tom Lane)

These functions used the result rowtype specified in the FROM ... AS clause without checking that it matched the actual rowtype of the supplied tuple value. If it didn't, that would usually result in a crash, though disclosure of server memory contents seems possible as well. (CVE-2017-15098)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

SecurityFix sample server-start scripts to become $PGUSER before opening $PGLOG

Changes

Fix sample server-start scripts to become $PGUSER before opening $PGLOG (Noah Misch)

Previously, the postmaster log file was opened while still running as root. The database owner could therefore mount an attack against another system user by making $PGLOG be a symbolic link to some other file, which would then become corrupted by appending log messages.

By default, these scripts are not installed anywhere. Users who have made use of them will need to manually recopy them, or apply the same changes to their modified versions. If the existing $PGLOG file is root-owned, it will need to be removed or renamed out of the way before restarting the server with the corrected script. (CVE-2017-12172)

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix BRIN index summarization to handle concurrent table extension correctly

Changes

Fix BRIN index summarization to handle concurrent table extension correctly (Álvaro Herrera)

Previously, a race condition allowed some table rows to be omitted from the index. It may be necessary to reindex existing BRIN indexes to recover from past occurrences of this problem.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix possible failures during concurrent updates of a BRIN index

Changes

Fix possible failures during concurrent updates of a BRIN index (Tom Lane)

These race conditions could result in errors like “invalid index offnum” or “inconsistent range map”.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent logical replication from setting non-replicated columns to nulls when replicating an UPDATE

Changes

Prevent logical replication from setting non-replicated columns to nulls when replicating an UPDATE (Petr Jelinek)

Bug fixesFix logical replication to fire BEFORE ROW DELETE triggers when expected

Changes

Fix logical replication to fire BEFORE ROW DELETE triggers when expected (Masahiko Sawada)

Previously, that failed to happen unless the table also had a BEFORE ROW UPDATE trigger.

Bug fixesFix crash when logical decoding is invoked from a SPI-using function, in particular any function written in a PL language

Changes

Fix crash when logical decoding is invoked from a SPI-using function, in particular any function written in a PL language (Tom Lane)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIgnore CTEs when looking up the target table for INSERT/UPDATE/DELETE, and prevent matching schema-qualified target table names to trigger transition table names

Changes

Ignore CTEs when looking up the target table for INSERT/UPDATE/DELETE, and prevent matching schema-qualified target table names to trigger transition table names (Thomas Munro)

This restores the pre-v10 behavior for CTEs attached to DML commands.

ImprovementsAvoid evaluating an aggregate function's argument expression(s) at rows where its FILTER test fails

Changes

Avoid evaluating an aggregate function's argument expression(s) at rows where its FILTER test fails (Tom Lane)

This restores the pre-v10 (and SQL-standard) behavior.

Bug fixesFix incorrect query results when multiple GROUPING SETS columns contain the same simple variable

Changes

Fix incorrect query results when multiple GROUPING SETS columns contain the same simple variable (Tom Lane)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix query-lifespan memory leakage while evaluating a set-returning function in a SELECT's target list

Changes

Fix query-lifespan memory leakage while evaluating a set-returning function in a SELECT's target list (Tom Lane)

ImprovementsAllow parallel execution of prepared statements with generic plans

Changes

Allow parallel execution of prepared statements with generic plans (Amit Kapila, Kuntal Ghosh)

Bug fixesFix incorrect parallelization decisions for nested queries

Changes

Fix incorrect parallelization decisions for nested queries (Amit Kapila, Kuntal Ghosh)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix parallel query handling to not fail when a recently-used role is dropped

Changes

Fix parallel query handling to not fail when a recently-used role is dropped (Amit Kapila)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix crash in parallel execution of a bitmap scan having a BitmapAnd plan node below a BitmapOr node

Changes

Fix crash in parallel execution of a bitmap scan having a BitmapAnd plan node below a BitmapOr node (Dilip Kumar)

Bug fixesFix json_build_array(), json_build_object(), and their jsonb equivalents to handle explicit VARIADIC arguments correctly

Changes

Fix json_build_array(), json_build_object(), and their jsonb equivalents to handle explicit VARIADIC arguments correctly (Michael Paquier)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix autovacuum's “work item” logic to prevent possible crashes and silent loss of work items

Changes

Fix autovacuum's “work item” logic to prevent possible crashes and silent loss of work items (Álvaro Herrera)

Bug fixesFix corner-case crashes when columns have been added to the end of a view

Changes

Fix corner-case crashes when columns have been added to the end of a view (Tom Lane)

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsRecord proper dependencies when a view or rule contains FieldSelect or FieldStore expression nodes

Changes

Record proper dependencies when a view or rule contains FieldSelect or FieldStore expression nodes (Tom Lane)

Lack of these dependencies could allow a column or data type DROP to go through when it ought to fail, thereby causing later uses of the view or rule to get errors. This patch does not do anything to protect existing views/rules, only ones created in the future.

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsCorrectly detect hashability of range data types

Changes

Correctly detect hashability of range data types (Tom Lane)

The planner mistakenly assumed that any range type could be hashed for use in hash joins or hash aggregation, but actually it must check whether the range's subtype has hash support. This does not affect any of the built-in range types, since they're all hashable anyway.

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsCorrectly ignore RelabelType expression nodes when examining functional-dependency statistics

Changes

Correctly ignore RelabelType expression nodes when examining functional-dependency statistics (David Rowley)

This allows, e.g., extended statistics on varchar columns to be used properly.

ImprovementsPrevent sharing transition states between ordered-set aggregates

Changes

Prevent sharing transition states between ordered-set aggregates (David Rowley)

This causes a crash with the built-in ordered-set aggregates, and probably with user-written ones as well. v11 and later will include provisions for dealing with such cases safely, but in released branches, just disable the optimization.

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsPrevent idle_in_transaction_session_timeout from being ignored when a statement_timeout occurred earlier

Changes

Prevent idle_in_transaction_session_timeout from being ignored when a statement_timeout occurred earlier (Lukas Fittl)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix low-probability loss of NOTIFY messages due to XID wraparound

Changes

Fix low-probability loss of NOTIFY messages due to XID wraparound (Marko Tiikkaja, Tom Lane)

If a session executed no queries, but merely listened for notifications, for more than 2 billion transactions, it started to miss some notifications from concurrently-committing transactions.

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsReduce the frequency of data flush requests during bulk file copies to avoid performance problems on macOS, particularly with its new APFS file system

Changes

Reduce the frequency of data flush requests during bulk file copies to avoid performance problems on macOS, particularly with its new APFS file system (Tom Lane)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsAllow COPY's FREEZE option to work when the transaction isolation level is REPEATABLE READ or higher

Changes

Allow COPY's FREEZE option to work when the transaction isolation level is REPEATABLE READ or higher (Noah Misch)

This case was unintentionally broken by a previous bug fix.

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix AggGetAggref() to return the correct Aggref nodes to aggregate final functions whose transition calculations have been merged

Changes

Fix AggGetAggref() to return the correct Aggref nodes to aggregate final functions whose transition calculations have been merged (Tom Lane)

Related records (1)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix insufficient schema-qualification in some new queries in pg_dump and psql

Changes

Fix insufficient schema-qualification in some new queries in pg_dump and psql (Vitaly Burovoy, Tom Lane, Noah Misch)

ImprovementsAvoid use of @> operator in psql's queries for \d

Changes

Avoid use of @> operator in psql's queries for \d (Tom Lane)

This prevents problems when the parray_gin extension is installed, since that defines a conflicting operator.

Bug fixesFix pg_basebackup's matching of tablespace paths to canonicalize both paths before comparing

Changes

Fix pg_basebackup's matching of tablespace paths to canonicalize both paths before comparing (Michael Paquier)

This is particularly helpful on Windows.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix libpq to not require user's home directory to exist

Changes

Fix libpq to not require user's home directory to exist (Tom Lane)

In v10, failure to find the home directory while trying to read ~/.pgpass was treated as a hard error, but it should just cause that file to not be found. Both v10 and previous release branches made the same mistake when reading ~/.pg_service.conf, though this was less obvious since that file is not sought unless a service name is specified.

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn ecpglib, correctly handle backslashes in string literals depending on whether standard_conforming_strings is set

Changes

In ecpglib, correctly handle backslashes in string literals depending on whether standard_conforming_strings is set (Tsunakawa Takayuki)

Related records (3)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsMake ecpglib's Informix-compatibility mode ignore fractional digits in integer input strings, as expected

Changes

Make ecpglib's Informix-compatibility mode ignore fractional digits in integer input strings, as expected (Gao Zengqi, Michael Meskes)

Related records (4)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

Bug fixesFix missing temp-install prerequisites for check-like Make targets

Changes

Fix missing temp-install prerequisites for check-like Make targets (Noah Misch)

Some non-default test procedures that are meant to work like make check failed to ensure that the temporary installation was up to date.

Related records (2)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsUpdate time zone data files to tzdata release 2017c for DST law changes in Fiji, Namibia, Northern Cyprus, Sudan, Tonga, and Turks & Caicos Islands, plus historical corrections for Alaska, Apia, Burma, Calcutta, Detroit, Ireland, Namibia, and Pago Pago.

Changes

Update time zone data files to tzdata release 2017c for DST law changes in Fiji, Namibia, Northern Cyprus, Sudan, Tonga, and Turks & Caicos Islands, plus historical corrections for Alaska, Apia, Burma, Calcutta, Detroit, Ireland, Namibia, and Pago Pago.

Related records (5)

“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.

ImprovementsIn the documentation, restore HTML anchors to being upper-case strings

Changes

In the documentation, restore HTML anchors to being upper-case strings (Peter Eisentraut)

Due to a toolchain change, the 10.0 user manual had lower-case strings for intrapage anchors, thus breaking some external links into our website documentation. Return to our previous convention of using upper-case strings.

How is this comparison generated?

The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.

Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.

Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.

CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.

Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.