↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 9.0

Read the English manual

End of life · Recorded build 9.0.23 · 2015-10-08

This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.

First stable release
2010-09-20
Support end
2015-10-08
Indexed releases
24
Original release-note entries
850

Manuals & provenance

PostgreSQL 9.0 English manual · 1086 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 9.0.0 · Changes from the initial release through 9.0.23

Original migration guidance for 9.0.0

A dump/restore using pg_dump, or use of pg_upgrade, is required for those wishing to migrate data from any previous release.

Version 9.0 contains a number of changes that selectively break backwards compatibility in order to support new features and code quality improvements. In particular, users who make extensive use of PL/pgSQL, Point-In-Time Recovery (PITR), or Warm Standby should test their applications because of slight user-visible changes in those areas. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
9.0.23 2015-10-08 472501
9.0.22 2015-06-12 2200
9.0.21 2015-06-04 3100
9.0.20 2015-05-22 351303
9.0.19 2015-02-05 522206
9.0.18 2014-07-24 281401
9.0.17 2014-03-20 10100
9.0.16 2014-02-20 371608
9.0.15 2013-12-05 161000
9.0.14 2013-10-10 261300
9.0.13 2013-04-04 211502
9.0.12 2013-02-07 23901
9.0.11 2012-12-06 322000
9.0.10 2012-09-24 10500
9.0.9 2012-08-17 231102
9.0.8 2012-06-04 271902
9.0.7 2012-02-27 351803
9.0.6 2011-12-05 291300
9.0.5 2011-09-26 643901
9.0.4 2011-04-18 291800
9.0.3 2011-01-31 12701
9.0.2 2010-12-16 422600
9.0.1 2010-10-04 10501
9.0.0 2010-09-20 2375200

Initial release changes

Original entries from 9.0.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

237 of 237 original entries.

  • Remove server parameter add_missing_from, which was defaulted to off for many years Compatibility Migration

    Remove server parameter add_missing_from, which was defaulted to off for many years (Tom Lane)

    Original release occurrence · 9.0.0/migration/001

  • Remove server parameter regex_flavor, which was defaulted to advanced for many years Compatibility Migration

    Remove server parameter regex_flavor, which was defaulted to advanced for many years (Tom Lane)

    Original release occurrence · 9.0.0/migration/002

  • archive_mode now only affects archive_command; a new setting, wal_level, affects the contents of the write-ahead log Compatibility Migration

    archive_mode now only affects archive_command; a new setting, wal_level, affects the contents of the write-ahead log (Heikki Linnakangas)

    Original release occurrence · 9.0.0/migration/003

  • log_temp_files now uses default file size units of kilobytes Compatibility Migration

    log_temp_files now uses default file size units of kilobytes (Robert Haas)

    Original release occurrence · 9.0.0/migration/004

  • When querying a parent table, do not do any separate permission checks on child tables scanned as part of the query Compatibility Migration

    When querying a parent table, do not do any separate permission checks on child tables scanned as part of the query (Peter Eisentraut)

    The SQL standard specifies this behavior, and it is also much more convenient in practice than the former behavior of checking permissions on each child as well as the parent.

    Original release occurrence · 9.0.0/migration/005

  • bytea output now appears in hex format by default Compatibility Migration

    bytea output now appears in hex format by default (Peter Eisentraut)

    The server parameter bytea_output can be used to select the traditional output format if needed for compatibility.

    Original release occurrence · 9.0.0/migration/006

  • Array input now considers only plain ASCII whitespace characters to be potentially ignorable; it will never ignore non-ASCII characters, even if they are whitespace according to some locales Compatibility Migration

    Array input now considers only plain ASCII whitespace characters to be potentially ignorable; it will never ignore non-ASCII characters, even if they are whitespace according to some locales (Tom Lane)

    This avoids some corner cases where array values could be interpreted differently depending on the server's locale settings.

    Original release occurrence · 9.0.0/migration/007

  • Improve standards compliance of SIMILAR TO patterns and SQL-style substring() patterns Compatibility Migration

    Improve standards compliance of SIMILAR TO patterns and SQL-style substring() patterns (Tom Lane)

    This includes treating ? and {...} as pattern metacharacters, while they were simple literal characters before; that corresponds to new features added in SQL:2008. Also, ^ and $ are now treated as simple literal characters; formerly they were treated as metacharacters, as if the pattern were following POSIX rather than SQL rules. Also, in SQL-standard substring(), use of parentheses for nesting no longer interferes with capturing of a substring. Also, processing of bracket expressions (character classes) is now more standards-compliant.

    Original release occurrence · 9.0.0/migration/008

  • Reject negative length values in 3-parameter substring() for bit strings, per the SQL standard Compatibility Migration

    Reject negative length values in 3-parameter substring() for bit strings, per the SQL standard (Tom Lane)

    Original release occurrence · 9.0.0/migration/009

  • Make date_trunc truncate rather than round when reducing precision of fractional seconds Compatibility Migration

    Make date_trunc truncate rather than round when reducing precision of fractional seconds (Tom Lane)

    The code always acted this way for integer-based dates/times. Now float-based dates/times behave similarly.

    Original release occurrence · 9.0.0/migration/010

  • Tighten enforcement of column name consistency during RENAME when a child table inherits the same column from multiple unrelated parents Compatibility Migration

    Tighten enforcement of column name consistency during RENAME when a child table inherits the same column from multiple unrelated parents (KaiGai Kohei)

    Original release occurrence · 9.0.0/migration/011

  • No longer automatically rename indexes and index columns when the underlying table columns are renamed Compatibility Migration

    No longer automatically rename indexes and index columns when the underlying table columns are renamed (Tom Lane)

    Administrators can still rename such indexes and columns manually. This change will require an update of the JDBC driver, and possibly other drivers, so that unique indexes are correctly recognized after a rename.

    Original release occurrence · 9.0.0/migration/012

  • CREATE OR REPLACE FUNCTION can no longer change the declared names of function parameters Compatibility Migration

    CREATE OR REPLACE FUNCTION can no longer change the declared names of function parameters (Pavel Stehule)

    In order to avoid creating ambiguity in named-parameter calls, it is no longer allowed to change the aliases for input parameters in the declaration of an existing function (although names can still be assigned to previously unnamed parameters). You now have to DROP and recreate the function to do that.

    Original release occurrence · 9.0.0/migration/013

  • PL/pgSQL now throws an error if a variable name conflicts with a column name used in a query Compatibility Migration

    PL/pgSQL now throws an error if a variable name conflicts with a column name used in a query (Tom Lane)

    The former behavior was to bind ambiguous names to PL/pgSQL variables in preference to query columns, which often resulted in surprising misbehavior. Throwing an error allows easy detection of ambiguous situations. Although it's recommended that functions encountering this type of error be modified to remove the conflict, the old behavior can be restored if necessary via the configuration parameter plpgsql.variable_conflict, or via the per-function option #variable_conflict.

    Original release occurrence · 9.0.0/migration/014

  • PL/pgSQL no longer allows variable names that match certain SQL reserved words Compatibility Migration

    PL/pgSQL no longer allows variable names that match certain SQL reserved words (Tom Lane)

    This is a consequence of aligning the PL/pgSQL parser to match the core SQL parser more closely. If necessary, variable names can be double-quoted to avoid this restriction.

    Original release occurrence · 9.0.0/migration/015

  • PL/pgSQL now requires columns of composite results to match the expected type modifier as well as base type Compatibility Migration

    PL/pgSQL now requires columns of composite results to match the expected type modifier as well as base type (Pavel Stehule, Tom Lane)

    For example, if a column of the result type is declared as NUMERIC(30,2), it is no longer acceptable to return a NUMERIC of some other precision in that column. Previous versions neglected to check the type modifier and would thus allow result rows that didn't actually conform to the declared restrictions.

    Original release occurrence · 9.0.0/migration/016

  • PL/pgSQL now treats selection into composite fields more consistently Compatibility Migration

    PL/pgSQL now treats selection into composite fields more consistently (Tom Lane)

    Formerly, a statement like SELECT ... INTO rec.fld FROM ... was treated as a scalar assignment even if the record field fld was of composite type. Now it is treated as a record assignment, the same as when the INTO target is a regular variable of composite type. So the values to be assigned to the field's subfields should be written as separate columns of the SELECT list, not as a ROW(...) construct as in previous versions.

    If you need to do this in a way that will work in both 9.0 and previous releases, you can write something like rec.fld := ROW(...) FROM ....

    Original release occurrence · 9.0.0/migration/017

  • Remove PL/pgSQL's RENAME declaration Compatibility Migration

    Remove PL/pgSQL's RENAME declaration (Tom Lane)

    Instead of RENAME, use ALIAS, which can now create an alias for any variable, not only dollar sign parameter names (such as $1) as before.

    Original release occurrence · 9.0.0/migration/018

  • Deprecate use of => as an operator name Compatibility Migration

    Deprecate use of => as an operator name (Robert Haas)

    Future versions of PostgreSQL will probably reject this operator name entirely, in order to support the SQL-standard notation for named function parameters. For the moment, it is still allowed, but a warning is emitted when such an operator is defined.

    Original release occurrence · 9.0.0/migration/019

  • Remove support for platforms that don't have a working 64-bit integer data type Compatibility Migration

    Remove support for platforms that don't have a working 64-bit integer data type (Tom Lane)

    It is believed all still-supported platforms have working 64-bit integer data types.

    Original release occurrence · 9.0.0/migration/020

  • Allow a standby server to accept read-only queries Features

    Allow a standby server to accept read-only queries (Simon Riggs, Heikki Linnakangas)

    This feature is called Hot Standby. There are new postgresql.conf and recovery.conf settings to control this feature, as well as extensive documentation.

    Original release occurrence · 9.0.0/changes/001

  • Allow write-ahead log (WAL) data to be streamed to a standby server Features

    Allow write-ahead log (WAL) data to be streamed to a standby server (Fujii Masao, Heikki Linnakangas)

    This feature is called Streaming Replication. Previously WAL data could be sent to standby servers only in units of entire WAL files (normally 16 megabytes each). Streaming Replication eliminates this inefficiency and allows updates on the master to be propagated to standby servers with very little delay. There are new postgresql.conf and recovery.conf settings to control this feature, as well as extensive documentation.

    Original release occurrence · 9.0.0/changes/002

  • Add pg_last_xlog_receive_location() and pg_last_xlog_replay_location(), which can be used to monitor standby server WAL activity Features

    Add pg_last_xlog_receive_location() and pg_last_xlog_replay_location(), which can be used to monitor standby server WAL activity (Simon Riggs, Fujii Masao, Heikki Linnakangas)

    Original release occurrence · 9.0.0/changes/003

  • Allow per-tablespace values to be set for sequential and random page cost estimates (seq_page_cost/random_page_cost) via ALTER TABLESPACE ... SET/RESET Features

    Allow per-tablespace values to be set for sequential and random page cost estimates (seq_page_cost/random_page_cost) via ALTER TABLESPACE ... SET/RESET (Robert Haas)

    Original release occurrence · 9.0.0/changes/004

  • Improve performance and reliability of EvalPlanQual rechecks in join queries Performance

    Improve performance and reliability of EvalPlanQual rechecks in join queries (Tom Lane)

    UPDATE, DELETE, and SELECT FOR UPDATE/SHARE queries that involve joins will now behave much better when encountering freshly-updated rows.

    Original release occurrence · 9.0.0/changes/005

  • Improve performance of TRUNCATE when the table was created or truncated earlier in the same transaction Performance

    Improve performance of TRUNCATE when the table was created or truncated earlier in the same transaction (Tom Lane)

    Original release occurrence · 9.0.0/changes/006

  • Improve performance of finding inheritance child tables Performance

    Improve performance of finding inheritance child tables (Tom Lane)

    Original release occurrence · 9.0.0/changes/007

  • Remove unnecessary outer joins Features

    Remove unnecessary outer joins (Robert Haas)

    Outer joins where the inner side is unique and not referenced above the join are unnecessary and are therefore now removed. This will accelerate many automatically generated queries, such as those created by object-relational mappers (ORMs).

    Original release occurrence · 9.0.0/changes/008

  • Allow IS NOT NULL restrictions to use indexes Features

    Allow IS NOT NULL restrictions to use indexes (Tom Lane)

    This is particularly useful for finding MAX()/MIN() values in indexes that contain many null values.

    Original release occurrence · 9.0.0/changes/009

  • Improve the optimizer's choices about when to use materialize nodes, and when to use sorting versus hashing for DISTINCT Features

    Improve the optimizer's choices about when to use materialize nodes, and when to use sorting versus hashing for DISTINCT (Tom Lane)

    Original release occurrence · 9.0.0/changes/010

  • Improve the optimizer's equivalence detection for expressions involving boolean <> operators Features

    Improve the optimizer's equivalence detection for expressions involving boolean <> operators (Tom Lane)

    Original release occurrence · 9.0.0/changes/011

  • Use the same random seed every time GEQO plans a query Features

    Use the same random seed every time GEQO plans a query (Andres Freund)

    While the Genetic Query Optimizer (GEQO) still selects random plans, it now always selects the same random plans for identical queries, thus giving more consistent performance. You can modify geqo_seed to experiment with alternative plans.

    Original release occurrence · 9.0.0/changes/012

  • Improve GEQO plan selection Features

    Improve GEQO plan selection (Tom Lane)

    This avoids the rare error "failed to make a valid plan", and should also improve planning speed.

    Original release occurrence · 9.0.0/changes/013

  • Improve ANALYZE to support inheritance-tree statistics Features

    Improve ANALYZE to support inheritance-tree statistics (Tom Lane)

    This is particularly useful for partitioned tables. However, autovacuum does not yet automatically re-analyze parent tables when child tables change.

    Original release occurrence · 9.0.0/changes/014

  • Improve autovacuum's detection of when re-analyze is necessary Features

    Improve autovacuum's detection of when re-analyze is necessary (Tom Lane)

    Original release occurrence · 9.0.0/changes/015

  • Improve optimizer's estimation for greater/less-than comparisons Features

    Improve optimizer's estimation for greater/less-than comparisons (Tom Lane)

    When looking up statistics for greater/less-than comparisons, if the comparison value is in the first or last histogram bucket, use an index (if available) to fetch the current actual column minimum or maximum. This greatly improves the accuracy of estimates for comparison values near the ends of the data range, particularly if the range is constantly changing due to addition of new data.

    Original release occurrence · 9.0.0/changes/016

  • Allow setting of number-of-distinct-values statistics using ALTER TABLE Features

    Allow setting of number-of-distinct-values statistics using ALTER TABLE (Robert Haas)

    This allows users to override the estimated number or percentage of distinct values for a column. This statistic is normally computed by ANALYZE, but the estimate can be poor, especially on tables with very large numbers of rows.

    Original release occurrence · 9.0.0/changes/017

  • Add support for RADIUS (Remote Authentication Dial In User Service) authentication Features

    Add support for RADIUS (Remote Authentication Dial In User Service) authentication (Magnus Hagander)

    Original release occurrence · 9.0.0/changes/018

  • Allow LDAP (Lightweight Directory Access Protocol) authentication to operate in "search/bind" mode Features

    Allow LDAP (Lightweight Directory Access Protocol) authentication to operate in "search/bind" mode (Robert Fleming, Magnus Hagander)

    This allows the user to be looked up first, then the system uses the DN (Distinguished Name) returned for that user.

    Original release occurrence · 9.0.0/changes/019

  • Add samehost and samenet designations to pg_hba.conf Features

    Add samehost and samenet designations to pg_hba.conf (Stef Walter)

    These match the server's IP address and subnet address respectively.

    Original release occurrence · 9.0.0/changes/020

  • Pass trusted SSL root certificate names to the client so the client can return an appropriate client certificate Features

    Pass trusted SSL root certificate names to the client so the client can return an appropriate client certificate (Craig Ringer)

    Original release occurrence · 9.0.0/changes/021

  • Add the ability for clients to set an application name, which is displayed in pg_stat_activity Features

    Add the ability for clients to set an application name, which is displayed in pg_stat_activity (Dave Page)

    This allows administrators to characterize database traffic and troubleshoot problems by source application.

    Original release occurrence · 9.0.0/changes/022

  • Add a SQLSTATE option (%e) to log_line_prefix Features

    Add a SQLSTATE option (%e) to log_line_prefix (Guillaume Smet)

    This allows users to compile statistics on errors and messages by error code number.

    Original release occurrence · 9.0.0/changes/023

  • Write to the Windows event log in UTF16 encoding Features

    Write to the Windows event log in UTF16 encoding (Itagaki Takahiro)

    Now there is true multilingual support for PostgreSQL log messages on Windows.

    Original release occurrence · 9.0.0/changes/024

  • Add pg_stat_reset_shared('bgwriter') to reset the cluster-wide shared statistics for the background writer Features

    Add pg_stat_reset_shared('bgwriter') to reset the cluster-wide shared statistics for the background writer (Greg Smith)

    Original release occurrence · 9.0.0/changes/025

  • Add pg_stat_reset_single_table_counters() and pg_stat_reset_single_function_counters() to allow resetting the statistics counters for individual tables and functions Features

    Add pg_stat_reset_single_table_counters() and pg_stat_reset_single_function_counters() to allow resetting the statistics counters for individual tables and functions (Magnus Hagander)

    Original release occurrence · 9.0.0/changes/026

  • Allow setting of configuration parameters based on database/role combinations Features

    Allow setting of configuration parameters based on database/role combinations (Alvaro Herrera)

    Previously only per-database and per-role settings were possible, not combinations. All role and database settings are now stored in the new pg_db_role_setting system catalog. A new psql command \drds shows these settings. The legacy system views pg_roles, pg_shadow, and pg_user do not show combination settings, and therefore no longer completely represent the configuration for a user or database.

    Original release occurrence · 9.0.0/changes/027

  • Add server parameter bonjour, which controls whether a Bonjour-enabled server advertises itself via Bonjour Features

    Add server parameter bonjour, which controls whether a Bonjour-enabled server advertises itself via Bonjour (Tom Lane)

    The default is off, meaning it does not advertise. This allows packagers to distribute Bonjour-enabled builds without worrying that individual users might not want the feature.

    Original release occurrence · 9.0.0/changes/028

  • Add server parameter enable_material, which controls the use of materialize nodes in the optimizer Features

    Add server parameter enable_material, which controls the use of materialize nodes in the optimizer (Robert Haas)

    The default is on. When off, the optimizer will not add materialize nodes purely for performance reasons, though they will still be used when necessary for correctness.

    Original release occurrence · 9.0.0/changes/029

  • Change server parameter log_temp_files to use default file size units of kilobytes Features

    Change server parameter log_temp_files to use default file size units of kilobytes (Robert Haas)

    Previously this setting was interpreted in bytes if no units were specified.

    Original release occurrence · 9.0.0/changes/030

  • Log changes of parameter values when postgresql.conf is reloaded Features

    Log changes of parameter values when postgresql.conf is reloaded (Peter Eisentraut)

    This lets administrators and security staff audit changes of database settings, and is also very convenient for checking the effects of postgresql.conf edits.

    Original release occurrence · 9.0.0/changes/031

  • Properly enforce superuser permissions for custom server parameters Features

    Properly enforce superuser permissions for custom server parameters (Tom Lane)

    Non-superusers can no longer issue ALTER ROLE/DATABASE SET for parameters that are not currently known to the server. This allows the server to correctly check that superuser-only parameters are only set by superusers. Previously, the SET would be allowed and then ignored at session start, making superuser-only custom parameters much less useful than they should be.

    Original release occurrence · 9.0.0/changes/032

  • Perform SELECT FOR UPDATE/SHARE processing after applying LIMIT, so the number of rows returned is always predictable Features

    Perform SELECT FOR UPDATE/SHARE processing after applying LIMIT, so the number of rows returned is always predictable (Tom Lane)

    Previously, changes made by concurrent transactions could cause a SELECT FOR UPDATE to unexpectedly return fewer rows than specified by its LIMIT. FOR UPDATE in combination with ORDER BY can still produce surprising results, but that can be corrected by placing FOR UPDATE in a subquery.

    Original release occurrence · 9.0.0/changes/033

  • Allow mixing of traditional and SQL-standard LIMIT/OFFSET syntax Features

    Allow mixing of traditional and SQL-standard LIMIT/OFFSET syntax (Tom Lane)

    Original release occurrence · 9.0.0/changes/034

  • Extend the supported frame options in window functions Features

    Extend the supported frame options in window functions (Hitoshi Harada)

    Frames can now start with CURRENT ROW, and the ROWS n PRECEDING/FOLLOWING options are now supported.

    Original release occurrence · 9.0.0/changes/035

  • Make SELECT INTO and CREATE TABLE AS return row counts to the client in their command tags Features

    Make SELECT INTO and CREATE TABLE AS return row counts to the client in their command tags (Boszormenyi Zoltan)

    This can save an entire round-trip to the client, allowing result counts and pagination to be calculated without an additional COUNT query.

    Original release occurrence · 9.0.0/changes/036

  • Support Unicode surrogate pairs (dual 16-bit representation) in U& strings and identifiers Features

    Support Unicode surrogate pairs (dual 16-bit representation) in U& strings and identifiers (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/037

  • Support Unicode escapes in E'...' strings Features

    Support Unicode escapes in E'...' strings (Marko Kreen)

    Original release occurrence · 9.0.0/changes/038

  • Speed up CREATE DATABASE by deferring flushes to disk Performance

    Speed up CREATE DATABASE by deferring flushes to disk (Andres Freund, Greg Stark)

    Original release occurrence · 9.0.0/changes/039

  • Allow comments on columns of tables, views, and composite types only, not other relation types such as indexes and TOAST tables Features

    Allow comments on columns of tables, views, and composite types only, not other relation types such as indexes and TOAST tables (Tom Lane)

    Original release occurrence · 9.0.0/changes/040

  • Allow the creation of enumerated types containing no values Features

    Allow the creation of enumerated types containing no values (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/041

  • Let values of columns having storage type MAIN remain on the main heap page unless the row cannot fit on a page Features

    Let values of columns having storage type MAIN remain on the main heap page unless the row cannot fit on a page (Kevin Grittner)

    Previously MAIN values were forced out to TOAST tables until the row size was less than one-quarter of the page size.

    Original release occurrence · 9.0.0/changes/042

  • Implement IF EXISTS for ALTER TABLE DROP COLUMN and ALTER TABLE DROP CONSTRAINT Features

    Implement IF EXISTS for ALTER TABLE DROP COLUMN and ALTER TABLE DROP CONSTRAINT (Andres Freund)

    Original release occurrence · 9.0.0/changes/043

  • Allow ALTER TABLE commands that rewrite tables to skip WAL logging Features

    Allow ALTER TABLE commands that rewrite tables to skip WAL logging (Itagaki Takahiro)

    Such operations either produce a new copy of the table or are rolled back, so WAL archiving can be skipped, unless running in continuous archiving mode. This reduces I/O overhead and improves performance.

    Original release occurrence · 9.0.0/changes/044

  • Fix failure of ALTER TABLE table ADD COLUMN col serial when done by non-owner of table Bug fixes

    Fix failure of ALTER TABLE table ADD COLUMN col serial when done by non-owner of table (Tom Lane)

    Original release occurrence · 9.0.0/changes/045

  • Add support for copying COMMENTS and STORAGE settings in CREATE TABLE ... LIKE commands Features

    Add support for copying COMMENTS and STORAGE settings in CREATE TABLE ... LIKE commands (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/046

  • Add a shortcut for copying all properties in CREATE TABLE ... LIKE commands Features

    Add a shortcut for copying all properties in CREATE TABLE ... LIKE commands (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/047

  • Add the SQL-standard CREATE TABLE ... OF type command Features

    Add the SQL-standard CREATE TABLE ... OF type command (Peter Eisentraut)

    This allows creation of a table that matches an existing composite type. Additional constraints and defaults can be specified in the command.

    Original release occurrence · 9.0.0/changes/048

  • Add deferrable unique constraints Features

    Add deferrable unique constraints (Dean Rasheed)

    This allows mass updates, such as UPDATE tab SET col = col + 1, to work reliably on columns that have unique indexes or are marked as primary keys. If the constraint is specified as DEFERRABLE it will be checked at the end of the statement, rather than after each row is updated. The constraint check can also be deferred until the end of the current transaction, allowing such updates to be spread over multiple SQL commands.

    Original release occurrence · 9.0.0/changes/049

  • Add exclusion constraints Features

    Add exclusion constraints (Jeff Davis)

    Exclusion constraints generalize uniqueness constraints by allowing arbitrary comparison operators, not just equality. They are created with the CREATE TABLE CONSTRAINT ... EXCLUDE clause. The most common use of exclusion constraints is to specify that column entries must not overlap, rather than simply not be equal. This is useful for time periods and other ranges, as well as arrays. This feature enhances checking of data integrity for many calendaring, time-management, and scientific applications.

    Original release occurrence · 9.0.0/changes/050

  • Improve uniqueness-constraint violation error messages to report the values causing the failure Features

    Improve uniqueness-constraint violation error messages to report the values causing the failure (Itagaki Takahiro)

    For example, a uniqueness constraint violation might now report Key (x)=(2) already exists.

    Original release occurrence · 9.0.0/changes/051

  • Add the ability to make mass permission changes across a whole schema using the new GRANT/REVOKE IN SCHEMA clause Features

    Add the ability to make mass permission changes across a whole schema using the new GRANT/REVOKE IN SCHEMA clause (Petr Jelinek)

    This simplifies management of object permissions and makes it easier to utilize database roles for application data security.

    Original release occurrence · 9.0.0/changes/052

  • Add ALTER DEFAULT PRIVILEGES command to control privileges of objects created later Features

    Add ALTER DEFAULT PRIVILEGES command to control privileges of objects created later (Petr Jelinek)

    This greatly simplifies the assignment of object privileges in a complex database application. Default privileges can be set for tables, views, sequences, and functions. Defaults may be assigned on a per-schema basis, or database-wide.

    Original release occurrence · 9.0.0/changes/053

  • Add the ability to control large object (BLOB) permissions with GRANT/REVOKE Features

    Add the ability to control large object (BLOB) permissions with GRANT/REVOKE (KaiGai Kohei)

    Formerly, any database user could read or modify any large object. Read and write permissions can now be granted and revoked per large object, and the ownership of large objects is tracked.

    Original release occurrence · 9.0.0/changes/054

  • Make LISTEN/NOTIFY store pending events in a memory queue, rather than in a system table Features

    Make LISTEN/NOTIFY store pending events in a memory queue, rather than in a system table (Joachim Wieland)

    This substantially improves performance, while retaining the existing features of transactional support and guaranteed delivery.

    Original release occurrence · 9.0.0/changes/055

  • Allow NOTIFY to pass an optional "payload" string to listeners Features

    Allow NOTIFY to pass an optional "payload" string to listeners (Joachim Wieland)

    This greatly improves the usefulness of LISTEN/NOTIFY as a general-purpose event queue system.

    Original release occurrence · 9.0.0/changes/056

  • Allow CLUSTER on all per-database system catalogs Features

    Allow CLUSTER on all per-database system catalogs (Tom Lane)

    Shared catalogs still cannot be clustered.

    Original release occurrence · 9.0.0/changes/057

  • Accept COPY ... CSV FORCE QUOTE * Features

    Accept COPY ... CSV FORCE QUOTE * (Itagaki Takahiro)

    Now * can be used as shorthand for "all columns" in the FORCE QUOTE clause.

    Original release occurrence · 9.0.0/changes/058

  • Add new COPY syntax that allows options to be specified inside parentheses Features

    Add new COPY syntax that allows options to be specified inside parentheses (Robert Haas, Emmanuel Cecchet)

    This allows greater flexibility for future COPY options. The old syntax is still supported, but only for pre-existing options.

    Original release occurrence · 9.0.0/changes/059

  • Allow EXPLAIN to output in XML, JSON, or YAML format Features

    Allow EXPLAIN to output in XML, JSON, or YAML format (Robert Haas, Greg Sabino Mullane)

    The new output formats are easily machine-readable, supporting the development of new tools for analysis of EXPLAIN output.

    Original release occurrence · 9.0.0/changes/060

  • Add new BUFFERS option to report query buffer usage during EXPLAIN ANALYZE Features

    Add new BUFFERS option to report query buffer usage during EXPLAIN ANALYZE (Itagaki Takahiro)

    This allows better query profiling for individual queries. Buffer usage is no longer reported in the output for log_statement_stats and related settings.

    Original release occurrence · 9.0.0/changes/061

  • Add hash usage information to EXPLAIN output Features

    Add hash usage information to EXPLAIN output (Robert Haas)

    Original release occurrence · 9.0.0/changes/062

  • Add new EXPLAIN syntax that allows options to be specified inside parentheses Features

    Add new EXPLAIN syntax that allows options to be specified inside parentheses (Robert Haas)

    This allows greater flexibility for future EXPLAIN options. The old syntax is still supported, but only for pre-existing options.

    Original release occurrence · 9.0.0/changes/063

  • Change VACUUM FULL to rewrite the entire table and rebuild its indexes, rather than moving individual rows around to compact space Features

    Change VACUUM FULL to rewrite the entire table and rebuild its indexes, rather than moving individual rows around to compact space (Itagaki Takahiro, Tom Lane)

    The previous method was usually slower and caused index bloat. Note that the new method will use more disk space transiently during VACUUM FULL; potentially as much as twice the space normally occupied by the table and its indexes.

    Original release occurrence · 9.0.0/changes/064

  • Add new VACUUM syntax that allows options to be specified inside parentheses Features

    Add new VACUUM syntax that allows options to be specified inside parentheses (Itagaki Takahiro)

    This allows greater flexibility for future VACUUM options. The old syntax is still supported, but only for pre-existing options.

    Original release occurrence · 9.0.0/changes/065

  • Allow an index to be named automatically by omitting the index name in CREATE INDEX Features

    Allow an index to be named automatically by omitting the index name in CREATE INDEX (Tom Lane)

    Original release occurrence · 9.0.0/changes/066

  • By default, multicolumn indexes are now named after all their columns; and index expression columns are now named based on their expressions Features

    By default, multicolumn indexes are now named after all their columns; and index expression columns are now named based on their expressions (Tom Lane)

    Original release occurrence · 9.0.0/changes/067

  • Reindexing shared system catalogs is now fully transactional and crash-safe Features

    Reindexing shared system catalogs is now fully transactional and crash-safe (Tom Lane)

    Formerly, reindexing a shared index was only allowed in standalone mode, and a crash during the operation could leave the index in worse condition than it was before.

    Original release occurrence · 9.0.0/changes/068

  • Add point_ops operator class for GiST Features

    Add point_ops operator class for GiST (Teodor Sigaev)

    This feature permits GiST indexing of point columns. The index can be used for several types of queries such as point <@ polygon (point is in polygon). This should make many PostGIS queries faster.

    Original release occurrence · 9.0.0/changes/069

  • Use red-black binary trees for GIN index creation Features

    Use red-black binary trees for GIN index creation (Teodor Sigaev)

    Red-black trees are self-balancing. This avoids slowdowns in cases where the input is in nonrandom order.

    Original release occurrence · 9.0.0/changes/070

  • Allow bytea values to be written in hex notation Features

    Allow bytea values to be written in hex notation (Peter Eisentraut)

    The server parameter bytea_output controls whether hex or traditional format is used for bytea output. Libpq's PQescapeByteaConn() function automatically uses the hex format when connected to PostgreSQL 9.0 or newer servers. However, pre-9.0 libpq versions will not correctly process hex format from newer servers.

    The new hex format will be directly compatible with more applications that use binary data, allowing them to store and retrieve it without extra conversion. It is also significantly faster to read and write than the traditional format.

    Original release occurrence · 9.0.0/changes/071

  • Allow server parameter extra_float_digits to be increased to 3 Features

    Allow server parameter extra_float_digits to be increased to 3 (Tom Lane)

    The previous maximum extra_float_digits setting was 2. There are cases where 3 digits are needed to dump and restore float4 values exactly. pg_dump will now use the setting of 3 when dumping from a server that allows it.

    Original release occurrence · 9.0.0/changes/072

  • Tighten input checking for int2vector values Features

    Tighten input checking for int2vector values (Caleb Welton)

    Original release occurrence · 9.0.0/changes/073

  • Add prefix support in synonym dictionaries Features

    Add prefix support in synonym dictionaries (Teodor Sigaev)

    Original release occurrence · 9.0.0/changes/074

  • Add filtering dictionaries Features

    Add filtering dictionaries (Teodor Sigaev)

    Filtering dictionaries allow tokens to be modified then passed to subsequent dictionaries.

    Original release occurrence · 9.0.0/changes/075

  • Allow underscores in email-address tokens Features

    Allow underscores in email-address tokens (Teodor Sigaev)

    Original release occurrence · 9.0.0/changes/076

  • Use more standards-compliant rules for parsing URL tokens Features

    Use more standards-compliant rules for parsing URL tokens (Tom Lane)

    Original release occurrence · 9.0.0/changes/077

  • Allow function calls to supply parameter names and match them to named parameters in the function definition Features

    Allow function calls to supply parameter names and match them to named parameters in the function definition (Pavel Stehule)

    For example, if a function is defined to take parameters a and b, it can be called with func(a := 7, b := 12) or func(b := 12, a := 7).

    Original release occurrence · 9.0.0/changes/078

  • Support locale-specific regular expression processing with UTF-8 server encoding Features

    Support locale-specific regular expression processing with UTF-8 server encoding (Tom Lane)

    Locale-specific regular expression functionality includes case-insensitive matching and locale-specific character classes. Previously, these features worked correctly for non-ASCII characters only if the database used a single-byte server encoding (such as LATIN1). They will still misbehave in multi-byte encodings other than UTF-8.

    Original release occurrence · 9.0.0/changes/079

  • Add support for scientific notation in to_char() (EEEE specification) Features

    Add support for scientific notation in to_char() (EEEE specification) (Pavel Stehule, Brendan Jurd)

    Original release occurrence · 9.0.0/changes/080

  • Make to_char() honor FM (fill mode) in Y, YY, and YYY specifications Features

    Make to_char() honor FM (fill mode) in Y, YY, and YYY specifications (Bruce Momjian, Tom Lane)

    It was already honored by YYYY.

    Original release occurrence · 9.0.0/changes/081

  • Fix to_char() to output localized numeric and monetary strings in the correct encoding on Windows Bug fixes

    Fix to_char() to output localized numeric and monetary strings in the correct encoding on Windows (Hiroshi Inoue, Itagaki Takahiro, Bruce Momjian)

    Original release occurrence · 9.0.0/changes/082

  • Correct calculations of "overlaps" and "contains" operations for polygons Bug fixes

    Correct calculations of "overlaps" and "contains" operations for polygons (Teodor Sigaev)

    The polygon && (overlaps) operator formerly just checked to see if the two polygons' bounding boxes overlapped. It now does a more correct check. The polygon @> and <@ (contains/contained by) operators formerly checked to see if one polygon's vertexes were all contained in the other; this can wrongly report "true" for some non-convex polygons. Now they check that all line segments of one polygon are contained in the other.

    Original release occurrence · 9.0.0/changes/083

  • Allow aggregate functions to use ORDER BY Features

    Allow aggregate functions to use ORDER BY (Andrew Gierth)

    For example, this is now supported: array_agg(a ORDER BY b). This is useful with aggregates for which the order of input values is significant, and eliminates the need to use a nonstandard subquery to determine the ordering.

    Original release occurrence · 9.0.0/changes/084

  • Multi-argument aggregate functions can now use DISTINCT Features

    Multi-argument aggregate functions can now use DISTINCT (Andrew Gierth)

    Original release occurrence · 9.0.0/changes/085

  • Add the string_agg() aggregate function to combine values into a single string Features

    Add the string_agg() aggregate function to combine values into a single string (Pavel Stehule)

    Original release occurrence · 9.0.0/changes/086

  • Aggregate functions that are called with DISTINCT are now passed NULL values if the aggregate transition function is not marked as STRICT Features

    Aggregate functions that are called with DISTINCT are now passed NULL values if the aggregate transition function is not marked as STRICT (Andrew Gierth)

    For example, agg(DISTINCT x) might pass a NULL x value to agg(). This is more consistent with the behavior in non-DISTINCT cases.

    Original release occurrence · 9.0.0/changes/087

  • Add get_bit() and set_bit() functions for bit strings, mirroring those for bytea Features

    Add get_bit() and set_bit() functions for bit strings, mirroring those for bytea (Leonardo F)

    Original release occurrence · 9.0.0/changes/088

  • Implement OVERLAY() (replace) for bit strings and bytea Features

    Implement OVERLAY() (replace) for bit strings and bytea (Leonardo F)

    Original release occurrence · 9.0.0/changes/089

  • Add pg_table_size() and pg_indexes_size() to provide a more user-friendly interface to the pg_relation_size() function Features

    Add pg_table_size() and pg_indexes_size() to provide a more user-friendly interface to the pg_relation_size() function (Bernd Helmle)

    Original release occurrence · 9.0.0/changes/090

  • Add has_sequence_privilege() for sequence permission checking Features

    Add has_sequence_privilege() for sequence permission checking (Abhijit Menon-Sen)

    Original release occurrence · 9.0.0/changes/091

  • Update the information_schema views to conform to SQL:2008 Features

    Update the information_schema views to conform to SQL:2008 (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/092

  • Make the information_schema views correctly display maximum octet lengths for char and varchar columns Features

    Make the information_schema views correctly display maximum octet lengths for char and varchar columns (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/093

  • Speed up information_schema privilege views Performance

    Speed up information_schema privilege views (Joachim Wieland)

    Original release occurrence · 9.0.0/changes/094

  • Support execution of anonymous code blocks using the DO statement Features

    Support execution of anonymous code blocks using the DO statement (Petr Jelinek, Joshua Tolley, Hannu Valtonen)

    This allows execution of server-side code without the need to create and delete a temporary function definition. Code can be executed in any language for which the user has permissions to define a function.

    Original release occurrence · 9.0.0/changes/095

  • Implement SQL-standard-compliant per-column triggers Features

    Implement SQL-standard-compliant per-column triggers (Itagaki Takahiro)

    Such triggers are fired only when the specified column(s) are affected by the query, e.g. appear in an UPDATE's SET list.

    Original release occurrence · 9.0.0/changes/096

  • Add the WHEN clause to CREATE TRIGGER to allow control over whether a trigger is fired Features

    Add the WHEN clause to CREATE TRIGGER to allow control over whether a trigger is fired (Itagaki Takahiro)

    While the same type of check can always be performed inside the trigger, doing it in an external WHEN clause can have performance benefits.

    Original release occurrence · 9.0.0/changes/097

  • Add the OR REPLACE clause to CREATE LANGUAGE Features

    Add the OR REPLACE clause to CREATE LANGUAGE (Tom Lane)

    This is helpful to optionally install a language if it does not already exist, and is particularly helpful now that PL/pgSQL is installed by default.

    Original release occurrence · 9.0.0/changes/098

  • Install PL/pgSQL by default Features

    Install PL/pgSQL by default (Bruce Momjian)

    The language can still be removed from a particular database if the administrator has security or performance concerns about making it available.

    Original release occurrence · 9.0.0/changes/099

  • Improve handling of cases where PL/pgSQL variable names conflict with identifiers used in queries within a function Features

    Improve handling of cases where PL/pgSQL variable names conflict with identifiers used in queries within a function (Tom Lane)

    The default behavior is now to throw an error when there is a conflict, so as to avoid surprising behaviors. This can be modified, via the configuration parameter plpgsql.variable_conflict or the per-function option #variable_conflict, to allow either the variable or the query-supplied column to be used. In any case PL/pgSQL will no longer attempt to substitute variables in places where they would not be syntactically valid.

    Original release occurrence · 9.0.0/changes/100

  • Make PL/pgSQL use the main lexer, rather than its own version Features

    Make PL/pgSQL use the main lexer, rather than its own version (Tom Lane)

    This ensures accurate tracking of the main system's behavior for details such as string escaping. Some user-visible details, such as the set of keywords considered reserved in PL/pgSQL, have changed in consequence.

    Original release occurrence · 9.0.0/changes/101

  • Avoid throwing an unnecessary error for an invalid record reference Features

    Avoid throwing an unnecessary error for an invalid record reference (Tom Lane)

    An error is now thrown only if the reference is actually fetched, rather than whenever the enclosing expression is reached. For example, many people have tried to do this in triggers:

    if TG_OP = 'INSERT' and NEW.col1 = ... then
    

    This will now actually work as expected.

    Original release occurrence · 9.0.0/changes/102

  • Improve PL/pgSQL's ability to handle row types with dropped columns Features

    Improve PL/pgSQL's ability to handle row types with dropped columns (Pavel Stehule)

    Original release occurrence · 9.0.0/changes/103

  • Allow input parameters to be assigned values within PL/pgSQL functions Features

    Allow input parameters to be assigned values within PL/pgSQL functions (Steve Prentice)

    Formerly, input parameters were treated as being declared CONST, so the function's code could not change their values. This restriction has been removed to simplify porting of functions from other DBMSes that do not impose the equivalent restriction. An input parameter now acts like a local variable initialized to the passed-in value.

    Original release occurrence · 9.0.0/changes/104

  • Improve error location reporting in PL/pgSQL Features

    Improve error location reporting in PL/pgSQL (Tom Lane)

    Original release occurrence · 9.0.0/changes/105

  • Add count and ALL options to MOVE FORWARD/BACKWARD in PL/pgSQL Features

    Add count and ALL options to MOVE FORWARD/BACKWARD in PL/pgSQL (Pavel Stehule)

    Original release occurrence · 9.0.0/changes/106

  • Allow PL/pgSQL's WHERE CURRENT OF to use a cursor variable Features

    Allow PL/pgSQL's WHERE CURRENT OF to use a cursor variable (Tom Lane)

    Original release occurrence · 9.0.0/changes/107

  • Allow PL/pgSQL's OPEN cursor FOR EXECUTE to use parameters Features

    Allow PL/pgSQL's OPEN cursor FOR EXECUTE to use parameters (Pavel Stehule, Itagaki Takahiro)

    This is accomplished with a new USING clause.

    Original release occurrence · 9.0.0/changes/108

  • Add new PL/Perl functions: quote_literal(), quote_nullable(), quote_ident(), encode_bytea(), decode_bytea(), looks_like_number(), encode_array_literal(), encode_array_constructor() Features

    Add new PL/Perl functions: quote_literal(), quote_nullable(), quote_ident(), encode_bytea(), decode_bytea(), looks_like_number(), encode_array_literal(), encode_array_constructor() (Tim Bunce)

    Original release occurrence · 9.0.0/changes/109

  • Add server parameter plperl.on_init to specify a PL/Perl initialization function Features

    Add server parameter plperl.on_init to specify a PL/Perl initialization function (Tim Bunce)

    plperl.on_plperl_init and plperl.on_plperlu_init are also available for initialization that is specific to the trusted or untrusted language respectively.

    Original release occurrence · 9.0.0/changes/110

  • Support END blocks in PL/Perl Features

    Support END blocks in PL/Perl (Tim Bunce)

    END blocks do not currently allow database access.

    Original release occurrence · 9.0.0/changes/111

  • Allow use strict in PL/Perl Features

    Allow use strict in PL/Perl (Tim Bunce)

    Perl strict checks can also be globally enabled with the new server parameter plperl.use_strict.

    Original release occurrence · 9.0.0/changes/112

  • Allow require in PL/Perl Features

    Allow require in PL/Perl (Tim Bunce)

    This basically tests to see if the module is loaded, and if not, generates an error. It will not allow loading of modules that the administrator has not preloaded via the initialization parameters.

    Original release occurrence · 9.0.0/changes/113

  • Allow use feature in PL/Perl if Perl version 5.10 or later is used Features

    Allow use feature in PL/Perl if Perl version 5.10 or later is used (Tim Bunce)

    Original release occurrence · 9.0.0/changes/114

  • Verify that PL/Perl return values are valid in the server encoding Features

    Verify that PL/Perl return values are valid in the server encoding (Andrew Dunstan)

    Original release occurrence · 9.0.0/changes/115

  • Add Unicode support in PL/Python Features

    Add Unicode support in PL/Python (Peter Eisentraut)

    Strings are automatically converted from/to the server encoding as necessary.

    Original release occurrence · 9.0.0/changes/116

  • Improve bytea support in PL/Python Features

    Improve bytea support in PL/Python (Caleb Welton)

    Bytea values passed into PL/Python are now represented as binary, rather than the PostgreSQL bytea text format. Bytea values containing null bytes are now also output properly from PL/Python. Passing of boolean, integer, and float values was also improved.

    Original release occurrence · 9.0.0/changes/117

  • Support arrays as parameters and return values in PL/Python Features

    Support arrays as parameters and return values in PL/Python (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/118

  • Improve mapping of SQL domains to Python types Features

    Improve mapping of SQL domains to Python types (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/119

  • Add Python 3 support to PL/Python Features

    Add Python 3 support to PL/Python (Peter Eisentraut)

    The new server-side language is called plpython3u. This cannot be used in the same session with the Python 2 server-side language.

    Original release occurrence · 9.0.0/changes/120

  • Improve error location and exception reporting in PL/Python Features

    Improve error location and exception reporting in PL/Python (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/121

  • Add an --analyze-only option to vacuumdb, to analyze without vacuuming Features

    Add an --analyze-only option to vacuumdb, to analyze without vacuuming (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/122

  • Add support for quoting/escaping the values of psql variables as SQL strings or identifiers Features

    Add support for quoting/escaping the values of psql variables as SQL strings or identifiers (Pavel Stehule, Robert Haas)

    For example, :'var' will produce the value of var quoted and properly escaped as a literal string, while :"var" will produce its value quoted and escaped as an identifier.

    Original release occurrence · 9.0.0/changes/123

  • Ignore a leading UTF-8-encoded Unicode byte-order marker in script files read by psql Features

    Ignore a leading UTF-8-encoded Unicode byte-order marker in script files read by psql (Itagaki Takahiro)

    This is enabled when the client encoding is UTF-8. It improves compatibility with certain editors, mostly on Windows, that insist on inserting such markers.

    Original release occurrence · 9.0.0/changes/124

  • Fix psql --file - to properly honor --single-transaction Bug fixes

    Fix psql --file - to properly honor --single-transaction (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/125

  • Avoid overwriting of psql's command-line history when two psql sessions are run concurrently Features

    Avoid overwriting of psql's command-line history when two psql sessions are run concurrently (Tom Lane)

    Original release occurrence · 9.0.0/changes/126

  • Improve psql's tab completion support Features

    Improve psql's tab completion support (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/127

  • Show \timing output when it is enabled, regardless of "quiet" mode Features

    Show \timing output when it is enabled, regardless of "quiet" mode (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/128

  • Improve display of wrapped columns in psql Features

    Improve display of wrapped columns in psql (Roger Leigh)

    This behavior is now the default. The previous formatting is available by using \pset linestyle old-ascii.

    Original release occurrence · 9.0.0/changes/129

  • Allow psql to use fancy Unicode line-drawing characters via \pset linestyle unicode Features

    Allow psql to use fancy Unicode line-drawing characters via \pset linestyle unicode (Roger Leigh)

    Original release occurrence · 9.0.0/changes/130

  • Make \d show child tables that inherit from the specified parent Features

    Make \d show child tables that inherit from the specified parent (Damien Clochard)

    \d shows only the number of child tables, while \d+ shows the names of all child tables.

    Original release occurrence · 9.0.0/changes/131

  • Show definitions of index columns in \d index_name Features

    Show definitions of index columns in \d index_name (Khee Chin)

    The definition is useful for expression indexes.

    Original release occurrence · 9.0.0/changes/132

  • Show a view's defining query only in \d+, not in \d Features

    Show a view's defining query only in \d+, not in \d (Peter Eisentraut)

    Always including the query was deemed overly verbose.

    Original release occurrence · 9.0.0/changes/133

  • Make pg_dump/pg_restore --clean also remove large objects Features

    Make pg_dump/pg_restore --clean also remove large objects (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/134

  • Fix pg_dump to properly dump large objects when standard_conforming_strings is enabled Bug fixes

    Fix pg_dump to properly dump large objects when standard_conforming_strings is enabled (Tom Lane)

    The previous coding could fail when dumping to an archive file and then generating script output from pg_restore.

    Original release occurrence · 9.0.0/changes/135

  • pg_restore now emits large-object data in hex format when generating script output Features

    pg_restore now emits large-object data in hex format when generating script output (Tom Lane)

    This could cause compatibility problems if the script is then loaded into a pre-9.0 server. To work around that, restore directly to the server, instead.

    Original release occurrence · 9.0.0/changes/136

  • Allow pg_dump to dump comments attached to columns of composite types (Taro Minowa (Higepon)) Features

    Allow pg_dump to dump comments attached to columns of composite types (Taro Minowa (Higepon))

    Original release occurrence · 9.0.0/changes/137

  • Make pg_dump --verbose output the pg_dump and server versions in text output mode Features

    Make pg_dump --verbose output the pg_dump and server versions in text output mode (Jim Cox, Tom Lane)

    These were already provided in custom output mode.

    Original release occurrence · 9.0.0/changes/138

  • pg_restore now complains if any command-line arguments remain after the switches and optional file name Features

    pg_restore now complains if any command-line arguments remain after the switches and optional file name (Tom Lane)

    Previously, it silently ignored any such arguments.

    Original release occurrence · 9.0.0/changes/139

  • Allow pg_ctl to be used safely to start the postmaster during a system reboot Features

    Allow pg_ctl to be used safely to start the postmaster during a system reboot (Tom Lane)

    Previously, pg_ctl's parent process could have been mistakenly identified as a running postmaster based on a stale postmaster lock file, resulting in a transient failure to start the database.

    Original release occurrence · 9.0.0/changes/140

  • Give pg_ctl the ability to initialize the database (by invoking initdb) Features

    Give pg_ctl the ability to initialize the database (by invoking initdb) (Zdenek Kotala)

    Original release occurrence · 9.0.0/changes/141

  • Add new libpq functions PQconnectdbParams() and PQconnectStartParams() Features

    Add new libpq functions PQconnectdbParams() and PQconnectStartParams() (Guillaume Lelarge)

    These functions are similar to PQconnectdb() and PQconnectStart() except that they accept a null-terminated array of connection options, rather than requiring all options to be provided in a single string.

    Original release occurrence · 9.0.0/changes/142

  • Add libpq functions PQescapeLiteral() and PQescapeIdentifier() Features

    Add libpq functions PQescapeLiteral() and PQescapeIdentifier() (Robert Haas)

    These functions return appropriately quoted and escaped SQL string literals and identifiers. The caller is not required to pre-allocate the string result, as is required by PQescapeStringConn().

    Original release occurrence · 9.0.0/changes/143

  • Add support for a per-user service file (.pg_service.conf), which is checked before the site-wide service file Features

    Add support for a per-user service file (.pg_service.conf), which is checked before the site-wide service file (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/144

  • Properly report an error if the specified libpq service cannot be found Features

    Properly report an error if the specified libpq service cannot be found (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/145

  • Add TCP keepalive settings in libpq Features

    Add TCP keepalive settings in libpq (Tollef Fog Heen, Fujii Masao, Robert Haas)

    Keepalive settings were already supported on the server end of TCP connections.

    Original release occurrence · 9.0.0/changes/146

  • Avoid extra system calls to block and unblock SIGPIPE in libpq, on platforms that offer alternative methods Features

    Avoid extra system calls to block and unblock SIGPIPE in libpq, on platforms that offer alternative methods (Jeremy Kerr)

    Original release occurrence · 9.0.0/changes/147

  • When a .pgpass-supplied password fails, mention where the password came from in the error message Features

    When a .pgpass-supplied password fails, mention where the password came from in the error message (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/148

  • Load all SSL certificates given in the client certificate file Features

    Load all SSL certificates given in the client certificate file (Tom Lane)

    This improves support for indirectly-signed SSL certificates.

    Original release occurrence · 9.0.0/changes/149

  • Add SQLDA (SQL Descriptor Area) support to ecpg Features

    Add SQLDA (SQL Descriptor Area) support to ecpg (Boszormenyi Zoltan)

    Original release occurrence · 9.0.0/changes/150

  • Add the DESCRIBE [ OUTPUT ] statement to ecpg Features

    Add the DESCRIBE [ OUTPUT ] statement to ecpg (Boszormenyi Zoltan)

    Original release occurrence · 9.0.0/changes/151

  • Add an ECPGtransactionStatus function to return the current transaction status Features

    Add an ECPGtransactionStatus function to return the current transaction status (Bernd Helmle)

    Original release occurrence · 9.0.0/changes/152

  • Add the string data type in ecpg Informix-compatibility mode Features

    Add the string data type in ecpg Informix-compatibility mode (Boszormenyi Zoltan)

    Original release occurrence · 9.0.0/changes/153

  • Allow ecpg to use new and old variable names without restriction Features

    Allow ecpg to use new and old variable names without restriction (Michael Meskes)

    Original release occurrence · 9.0.0/changes/154

  • Allow ecpg to use variable names in free() Features

    Allow ecpg to use variable names in free() (Michael Meskes)

    Original release occurrence · 9.0.0/changes/155

  • Make ecpg_dynamic_type() return zero for non-SQL3 data types Features

    Make ecpg_dynamic_type() return zero for non-SQL3 data types (Michael Meskes)

    Previously it returned the negative of the data type OID. This could be confused with valid type OIDs, however.

    Original release occurrence · 9.0.0/changes/156

  • Support long long types on platforms that already have 64-bit long Features

    Support long long types on platforms that already have 64-bit long (Michael Meskes)

    Original release occurrence · 9.0.0/changes/157

  • Add out-of-scope cursor support in ecpg's native mode Features

    Add out-of-scope cursor support in ecpg's native mode (Boszormenyi Zoltan)

    This allows DECLARE to use variables that are not in scope when OPEN is called. This facility already existed in ecpg's Informix-compatibility mode.

    Original release occurrence · 9.0.0/changes/158

  • Allow dynamic cursor names in ecpg Features

    Allow dynamic cursor names in ecpg (Boszormenyi Zoltan)

    Original release occurrence · 9.0.0/changes/159

  • Allow ecpg to use noise words FROM and IN in FETCH and MOVE Features

    Allow ecpg to use noise words FROM and IN in FETCH and MOVE (Boszormenyi Zoltan)

    Original release occurrence · 9.0.0/changes/160

  • Enable client thread safety by default Features

    Enable client thread safety by default (Bruce Momjian)

    The thread-safety option can be disabled with configure --disable-thread-safety.

    Original release occurrence · 9.0.0/changes/161

  • Add support for controlling the Linux out-of-memory killer Features

    Add support for controlling the Linux out-of-memory killer (Alex Hunsaker, Tom Lane)

    Now that /proc/self/oom_adj allows disabling of the Linux out-of-memory (OOM) killer, it's recommendable to disable OOM kills for the postmaster. It may then be desirable to re-enable OOM kills for the postmaster's child processes. The new compile-time option LINUX_OOM_ADJ allows the killer to be reactivated for child processes.

    Original release occurrence · 9.0.0/changes/162

  • New Makefile targets world, install-world, and installcheck-world Features

    New Makefile targets world, install-world, and installcheck-world (Andrew Dunstan)

    These are similar to the existing all, install, and installcheck targets, but they also build the HTML documentation, build and test contrib, and test server-side languages and ecpg.

    Original release occurrence · 9.0.0/changes/163

  • Add data and documentation installation location control to PGXS Makefiles Features

    Add data and documentation installation location control to PGXS Makefiles (Mark Cave-Ayland)

    Original release occurrence · 9.0.0/changes/164

  • Add Makefile rules to build the PostgreSQL documentation as a single HTML file or as a single plain-text file Features

    Add Makefile rules to build the PostgreSQL documentation as a single HTML file or as a single plain-text file (Peter Eisentraut, Bruce Momjian)

    Original release occurrence · 9.0.0/changes/165

  • Support compiling on 64-bit Windows and running in 64-bit mode Features

    Support compiling on 64-bit Windows and running in 64-bit mode (Tsutomu Yamada, Magnus Hagander)

    This allows for large shared memory sizes on Windows.

    Original release occurrence · 9.0.0/changes/166

  • Support server builds using Visual Studio 2008 Features

    Support server builds using Visual Studio 2008 (Magnus Hagander)

    Original release occurrence · 9.0.0/changes/167

  • Distribute prebuilt documentation in a subdirectory tree, rather than as tar archive files inside the distribution tarball Features

    Distribute prebuilt documentation in a subdirectory tree, rather than as tar archive files inside the distribution tarball (Peter Eisentraut)

    For example, the prebuilt HTML documentation is now in doc/src/sgml/html/; the manual pages are packaged similarly.

    Original release occurrence · 9.0.0/changes/168

  • Make the server's lexer reentrant Features

    Make the server's lexer reentrant (Tom Lane)

    This was needed for use of the lexer by PL/pgSQL.

    Original release occurrence · 9.0.0/changes/169

  • Improve speed of memory allocation Features

    Improve speed of memory allocation (Tom Lane, Greg Stark)

    Original release occurrence · 9.0.0/changes/170

  • User-defined constraint triggers now have entries in pg_constraint as well as pg_trigger Features

    User-defined constraint triggers now have entries in pg_constraint as well as pg_trigger (Tom Lane)

    Because of this change, pg_constraint.pgconstrname is now redundant and has been removed.

    Original release occurrence · 9.0.0/changes/171

  • Add system catalog columns pg_constraint.conindid and pg_trigger.tgconstrindid to better document the use of indexes for constraint enforcement Features

    Add system catalog columns pg_constraint.conindid and pg_trigger.tgconstrindid to better document the use of indexes for constraint enforcement (Tom Lane)

    Original release occurrence · 9.0.0/changes/172

  • Allow multiple conditions to be communicated to backends using a single operating system signal Features

    Allow multiple conditions to be communicated to backends using a single operating system signal (Fujii Masao)

    This allows new features to be added without a platform-specific constraint on the number of signal conditions.

    Original release occurrence · 9.0.0/changes/173

  • Improve source code test coverage, including contrib, PL/Python, and PL/Perl Features

    Improve source code test coverage, including contrib, PL/Python, and PL/Perl (Peter Eisentraut, Andrew Dunstan)

    Original release occurrence · 9.0.0/changes/174

  • Remove the use of flat files for system table bootstrapping Features

    Remove the use of flat files for system table bootstrapping (Tom Lane, Alvaro Herrera)

    This improves performance when using many roles or databases, and eliminates some possible failure conditions.

    Original release occurrence · 9.0.0/changes/175

  • Automatically generate the initial contents of pg_attribute for "bootstrapped" catalogs Features

    Automatically generate the initial contents of pg_attribute for "bootstrapped" catalogs (John Naylor)

    This greatly simplifies changes to these catalogs.

    Original release occurrence · 9.0.0/changes/176

  • Split the processing of INSERT/UPDATE/DELETE operations out of execMain.c Features

    Split the processing of INSERT/UPDATE/DELETE operations out of execMain.c (Marko Tiikkaja)

    Updates are now executed in a separate ModifyTable node. This change is necessary infrastructure for future improvements.

    Original release occurrence · 9.0.0/changes/177

  • Simplify translation of psql's SQL help text Features

    Simplify translation of psql's SQL help text (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/178

  • Reduce the lengths of some file names so that all file paths in the distribution tarball are less than 100 characters Features

    Reduce the lengths of some file names so that all file paths in the distribution tarball are less than 100 characters (Tom Lane)

    Some decompression programs have problems with longer file paths.

    Original release occurrence · 9.0.0/changes/179

  • Add a new ERRCODE_INVALID_PASSWORD SQLSTATE error code Features

    Add a new ERRCODE_INVALID_PASSWORD SQLSTATE error code (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/180

  • With authors' permissions, remove the few remaining personal source code copyright notices Features

    With authors' permissions, remove the few remaining personal source code copyright notices (Bruce Momjian)

    The personal copyright notices were insignificant but the community occasionally had to answer questions about them.

    Original release occurrence · 9.0.0/changes/181

  • Add new documentation section about running PostgreSQL in non-durable mode to improve performance Performance

    Add new documentation section about running PostgreSQL in non-durable mode to improve performance (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/182

  • Restructure the HTML documentation Makefile rules to make their dependency checks work correctly, avoiding unnecessary rebuilds Features

    Restructure the HTML documentation Makefile rules to make their dependency checks work correctly, avoiding unnecessary rebuilds (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/183

  • Use DocBook XSL stylesheets for man page building, rather than Docbook2X Features

    Use DocBook XSL stylesheets for man page building, rather than Docbook2X (Peter Eisentraut)

    This changes the set of tools needed to build the man pages.

    Original release occurrence · 9.0.0/changes/184

  • Improve PL/Perl code structure Features

    Improve PL/Perl code structure (Tim Bunce)

    Original release occurrence · 9.0.0/changes/185

  • Improve error context reports in PL/Perl Features

    Improve error context reports in PL/Perl (Alexey Klyukin)

    Original release occurrence · 9.0.0/changes/186

  • Require Autoconf 2.63 to build configure Features

    Require Autoconf 2.63 to build configure (Peter Eisentraut)

    Original release occurrence · 9.0.0/changes/187

  • Require Flex 2.5.31 or later to build from a CVS checkout Features

    Require Flex 2.5.31 or later to build from a CVS checkout (Tom Lane)

    Original release occurrence · 9.0.0/changes/188

  • Require Perl version 5.8 or later to build from a CVS checkout Features

    Require Perl version 5.8 or later to build from a CVS checkout (John Naylor, Andrew Dunstan)

    Original release occurrence · 9.0.0/changes/189

  • Use a more modern API for Bonjour Features

    Use a more modern API for Bonjour (Tom Lane)

    Bonjour support now requires OS X 10.3 or later. The older API has been deprecated by Apple.

    Original release occurrence · 9.0.0/changes/190

  • Add spinlock support for the SuperH architecture Features

    Add spinlock support for the SuperH architecture (Nobuhiro Iwamatsu)

    Original release occurrence · 9.0.0/changes/191

  • Allow non-GCC compilers to use inline functions if they support them Features

    Allow non-GCC compilers to use inline functions if they support them (Kurt Harriman)

    Original release occurrence · 9.0.0/changes/192

  • Remove support for platforms that don't have a working 64-bit integer data type Features

    Remove support for platforms that don't have a working 64-bit integer data type (Tom Lane)

    Original release occurrence · 9.0.0/changes/193

  • Restructure use of LDFLAGS to be more consistent across platforms Features

    Restructure use of LDFLAGS to be more consistent across platforms (Tom Lane)

    LDFLAGS is now used for linking both executables and shared libraries, and we add on LDFLAGS_EX when linking executables, or LDFLAGS_SL when linking shared libraries.

    Original release occurrence · 9.0.0/changes/194

  • Make backend header files safe to include in C++ Features

    Make backend header files safe to include in C++ (Kurt Harriman, Peter Eisentraut)

    These changes remove keyword conflicts that previously made C++ usage difficult in backend code. However, there are still other complexities when using C++ for backend functions. extern "C" { } is still necessary in appropriate places, and memory management and error handling are still problematic.

    Original release occurrence · 9.0.0/changes/195

  • Add AggCheckCallContext() for use in detecting if a C function is being called as an aggregate Features

    Add AggCheckCallContext() for use in detecting if a C function is being called as an aggregate (Hitoshi Harada)

    Original release occurrence · 9.0.0/changes/196

  • Change calling convention for SearchSysCache() and related functions to avoid hard-wiring the maximum number of cache keys Features

    Change calling convention for SearchSysCache() and related functions to avoid hard-wiring the maximum number of cache keys (Robert Haas)

    Existing calls will still work for the moment, but can be expected to break in 9.1 or later if not converted to the new style.

    Original release occurrence · 9.0.0/changes/197

  • Require calls of fastgetattr() and heap_getattr() backend macros to provide a non-NULL fourth argument Features

    Require calls of fastgetattr() and heap_getattr() backend macros to provide a non-NULL fourth argument (Robert Haas)

    Original release occurrence · 9.0.0/changes/198

  • Custom typanalyze functions should no longer rely on VacAttrStats.attr to determine the type of data they will be passed Features

    Custom typanalyze functions should no longer rely on VacAttrStats.attr to determine the type of data they will be passed (Tom Lane)

    This was changed to allow collection of statistics on index columns for which the storage type is different from the underlying column data type. There are new fields that tell the actual datatype being analyzed.

    Original release occurrence · 9.0.0/changes/199

  • Add parser hooks for processing ColumnRef and ParamRef nodes Features

    Add parser hooks for processing ColumnRef and ParamRef nodes (Tom Lane)

    Original release occurrence · 9.0.0/changes/200

  • Add a ProcessUtility hook so loadable modules can control utility commands Features

    Add a ProcessUtility hook so loadable modules can control utility commands (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/201

  • Add contrib/pg_upgrade to support in-place upgrades Features

    Add contrib/pg_upgrade to support in-place upgrades (Bruce Momjian)

    This avoids the requirement of dumping/reloading the database when upgrading to a new major release of PostgreSQL, thus reducing downtime by orders of magnitude. It supports upgrades to 9.0 from PostgreSQL 8.3 and 8.4.

    Original release occurrence · 9.0.0/changes/202

  • Add support for preserving relation relfilenode values during binary upgrades Features

    Add support for preserving relation relfilenode values during binary upgrades (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/203

  • Add support for preserving pg_type and pg_enum OIDs during binary upgrades Features

    Add support for preserving pg_type and pg_enum OIDs during binary upgrades (Bruce Momjian)

    Original release occurrence · 9.0.0/changes/204

  • Move data files within tablespaces into PostgreSQL-version-specific subdirectories Features

    Move data files within tablespaces into PostgreSQL-version-specific subdirectories (Bruce Momjian)

    This simplifies binary upgrades.

    Original release occurrence · 9.0.0/changes/205

  • Add multithreading option (-j) to contrib/pgbench Features

    Add multithreading option (-j) to contrib/pgbench (Itagaki Takahiro)

    This allows multiple CPUs to be used by pgbench, reducing the risk of pgbench itself becoming the test bottleneck.

    Original release occurrence · 9.0.0/changes/206

  • Add \shell and \setshell meta commands to contrib/pgbench Features

    Add \shell and \setshell meta commands to contrib/pgbench (Michael Paquier)

    Original release occurrence · 9.0.0/changes/207

  • New features for contrib/dict_xsyn Features

    New features for contrib/dict_xsyn (Sergey Karpov)

    The new options are matchorig, matchsynonyms, and keepsynonyms.

    Original release occurrence · 9.0.0/changes/208

  • Add full text dictionary contrib/unaccent Features

    Add full text dictionary contrib/unaccent (Teodor Sigaev)

    This filtering dictionary removes accents from letters, which makes full-text searches over multiple languages much easier.

    Original release occurrence · 9.0.0/changes/209

  • Add dblink_get_notify() to contrib/dblink Features

    Add dblink_get_notify() to contrib/dblink (Marcus Kempe)

    This allows asynchronous notifications in dblink.

    Original release occurrence · 9.0.0/changes/210

  • Improve contrib/dblink's handling of dropped columns Features

    Improve contrib/dblink's handling of dropped columns (Tom Lane)

    This affects dblink_build_sql_insert() and related functions. These functions now number columns according to logical not physical column numbers.

    Original release occurrence · 9.0.0/changes/211

  • Greatly increase contrib/hstore's data length limit, and add B-tree and hash support so GROUP BY and DISTINCT operations are possible on hstore columns Features

    Greatly increase contrib/hstore's data length limit, and add B-tree and hash support so GROUP BY and DISTINCT operations are possible on hstore columns (Andrew Gierth)

    New functions and operators were also added. These improvements make hstore a full-function key-value store embedded in PostgreSQL.

    Original release occurrence · 9.0.0/changes/212

  • Add contrib/passwordcheck to support site-specific password strength policies Features

    Add contrib/passwordcheck to support site-specific password strength policies (Laurenz Albe)

    The source code of this module should be modified to implement site-specific password policies.

    Original release occurrence · 9.0.0/changes/213

  • Add contrib/pg_archivecleanup tool Features

    Add contrib/pg_archivecleanup tool (Simon Riggs)

    This is designed to be used in the archive_cleanup_command server parameter, to remove no-longer-needed archive files.

    Original release occurrence · 9.0.0/changes/214

  • Add query text to contrib/auto_explain output Features

    Add query text to contrib/auto_explain output (Andrew Dunstan)

    Original release occurrence · 9.0.0/changes/215

  • Add buffer access counters to contrib/pg_stat_statements Features

    Add buffer access counters to contrib/pg_stat_statements (Itagaki Takahiro)

    Original release occurrence · 9.0.0/changes/216

  • Update contrib/start-scripts/linux to use /proc/self/oom_adj to disable the Linux out-of-memory (OOM) killer Features

    Update contrib/start-scripts/linux to use /proc/self/oom_adj to disable the Linux out-of-memory (OOM) killer (Alex Hunsaker, Tom Lane)

    Original release occurrence · 9.0.0/changes/217

Security evidence

30 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2015-5288 · Memory leak in crypt() function. CVSS 3.1

Fixed in this branch: 9.0.23. Component: contrib module.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2015-3167 · pgcrypto has multiple error messages for decryption with an incorrect key. CVSS 3.7

Fixed in this branch: 9.0.20. Component: contrib module.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2015-3166 · Unanticipated errors from the standard library. CVSS 5.6

Fixed in this branch: 9.0.20. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Release-note mentions:

CVE-2015-3165 · Double "free" after authentication timeout CVSS 7.5

Fixed in this branch: 9.0.20. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2015-0244 · An error in extended protocol message reading. CVSS 8.1

Fixed in this branch: 9.0.19. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2015-0243 · Memory errors in functions in the pgcrypto extension. CVSS 6.5

Fixed in this branch: 9.0.19. Component: contrib module.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2015-0242 · Buffer overrun in replacement printf family of functions. CVSS 4.2

Fixed in this branch: 9.0.19. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2015-0241 · Buffer overruns in "to_char" functions. CVSS 4.2

Fixed in this branch: 9.0.19. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2014-8161 · Constraint violation errors can cause display of values in columns which the user would not normally have rights to see. CVSS 3.1

Fixed in this branch: 9.0.19. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2014-0067 · Unauthenticated users may gain access to the database server during "make check".. CVSS 7.0
CVE-2014-0066 · Potential null pointer dereference crash when crypt(3) returns NULL. CVSS 0.0

Fixed in this branch: 9.0.16. Component: contrib module.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

Release-note mentions:

CVE-2014-0065 · Potential buffer overruns of fixed-size buffers. CVSS 0.0

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N

Release-note mentions:

CVE-2014-0064 · Potential buffer overruns due to integer overflow in size calculations. CVSS 6.5

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2014-0063 · Potential buffer overruns in datetime input/output. CVSS 4.3

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2014-0062 · Race condition in CREATE INDEX allows for privilege escalation. CVSS 8.8

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2014-0061 · Privilege escalation via calls to validator functions. CVSS 7.5

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2014-0060 · SET ROLE bypasses lack of ADMIN OPTION. CVSS 3.1

Fixed in this branch: 9.0.16. Component: core server.

Official affected-branch entry: 9.0.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2013-1900 · Random numbers generated by contrib/pgcrypto functions may be easy for another database user to guess

Fixed in this branch: 9.0.13.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2013-1899 · A connection request containing a database name that begins with "-" may be crafted to damage or destroy files within a server's data directory

Fixed in this branch: 9.0.13.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2013-0255 · executing enum_recv() with wrong parameters crashes server

Fixed in this branch: 9.0.12.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-3489 · xml_parse() DTD validation can be used to read arbitrary files
CVE-2012-3488 · contrib/xml2's xslt_process() can be used to read and write arbitrary files

Fixed in this branch: 9.0.9.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-2655 · SECURITY DEFINER and SET attributes on procedural call handlers are not ignored and can be used to crash the server

Fixed in this branch: 9.0.8.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-2143 · Passwords containing the byte 0x80 passed to the crypt() function in pgcrypto are incorrectly truncated if DES encryption was used

Fixed in this branch: 9.0.8.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

Fixed in this branch: 9.0.7.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-0867 · SSL certificate name checks are truncated to 32 characters, allowing connection spoofing under some circumstances when using third party certificate authorities.

Fixed in this branch: 9.0.7.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2012-0866 · Permissions on a function called by a trigger are not properly checked.

Fixed in this branch: 9.0.7.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2011-2483 · CVE-2011-2483

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2010-4015 · An authenticated database user can cause a buffer overrun by calling functions from the intarray optional module with certain parameters.

Fixed in this branch: 9.0.3.

Official affected-branch entry: 9.0.

Release-note mentions:

CVE-2010-3433 · An authenticated database user can manipulate modules and tied variables in some external procedural languages to execute code with enhanced privileges.Details

Fixed in this branch: 9.0.1.

Official affected-branch entry: 9.0.

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases