PostgreSQL 9.5
Read the English manualEnd of life · Recorded build 9.5.25 · 2021-02-11
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2016-01-07
- Support end
- 2021-02-11
- Indexed releases
- 26
- Original release-note entries
- 1026
Manuals & provenance
PostgreSQL 9.5 English manual · 1029 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 9.5.0 · Changes from the initial release through 9.5.25
Original migration guidance for 9.5.0
A dump/restore using pg_dumpall, or use of pg_upgrade, is required for those wishing to migrate data from any previous release.
Version 9.5 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 9.5.25 | 2021-02-11 | 32 | 15 | 0 | 0 |
| 9.5.24 | 2020-11-12 | 34 | 10 | 0 | 3 |
| 9.5.23 | 2020-08-13 | 25 | 11 | 0 | 2 |
| 9.5.22 | 2020-05-14 | 33 | 14 | 0 | 0 |
| 9.5.21 | 2020-02-13 | 29 | 16 | 0 | 0 |
| 9.5.20 | 2019-11-14 | 50 | 19 | 0 | 0 |
| 9.5.19 | 2019-08-08 | 20 | 7 | 0 | 2 |
| 9.5.18 | 2019-06-20 | 14 | 8 | 0 | 0 |
| 9.5.17 | 2019-05-09 | 31 | 18 | 0 | 2 |
| 9.5.16 | 2019-02-14 | 39 | 22 | 0 | 0 |
| 9.5.15 | 2018-11-08 | 52 | 25 | 0 | 0 |
| 9.5.14 | 2018-08-09 | 30 | 14 | 0 | 2 |
| 9.5.13 | 2018-05-10 | 38 | 20 | 0 | 0 |
| 9.5.12 | 2018-03-01 | 7 | 4 | 0 | 1 |
| 9.5.11 | 2018-02-08 | 32 | 18 | 0 | 1 |
| 9.5.10 | 2017-11-09 | 28 | 14 | 0 | 3 |
| 9.5.9 | 2017-08-31 | 8 | 2 | 0 | 0 |
| 9.5.8 | 2017-08-10 | 56 | 30 | 0 | 4 |
| 9.5.7 | 2017-05-11 | 40 | 23 | 0 | 4 |
| 9.5.6 | 2017-02-09 | 56 | 29 | 0 | 0 |
| 9.5.5 | 2016-10-27 | 47 | 22 | 0 | 0 |
| 9.5.4 | 2016-08-11 | 51 | 23 | 0 | 2 |
| 9.5.3 | 2016-05-12 | 25 | 14 | 0 | 0 |
| 9.5.2 | 2016-03-31 | 33 | 20 | 0 | 2 |
| 9.5.1 | 2016-02-11 | 23 | 12 | 0 | 2 |
| 9.5.0 | 2016-01-07 | 193 | 1 | 12 | 0 |
Initial release changes
Original entries from 9.5.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
193 of 193 original entries.
Adjust operator precedence to match the SQL standard Compatibility Migration
Adjust operator precedence to match the SQL standard (Tom Lane)
The precedence of <=, >= and <> has been reduced to match that of <, > and =. The precedence of IS tests (e.g., x IS NULL) has been reduced to be just below these six comparison operators. Also, multi-keyword operators beginning with NOT now have the precedence of their base operator (for example, NOT BETWEEN now has the same precedence as BETWEEN) whereas before they had inconsistent precedence, behaving like NOT with respect to their left operand but like their base operator with respect to their right operand. The new configuration parameter operator_precedence_warning can be enabled to warn about queries in which these precedence changes result in different parsing choices.
Original release occurrence ·
9.5.0/migration/001Change pg_ctl's default shutdown mode from smart to fast Compatibility Migration
Change pg_ctl's default shutdown mode from smart to fast (Bruce Momjian)
This means the default behavior will be to forcibly cancel existing database sessions, not simply wait for them to exit.
Original release occurrence ·
9.5.0/migration/002Use assignment cast behavior for data type conversions in PL/pgSQL assignments, rather than converting to and from text Compatibility Migration
Use assignment cast behavior for data type conversions in PL/pgSQL assignments, rather than converting to and from text (Tom Lane)
This change causes conversions of Booleans to strings to produce true or false, not t or f. Other type conversions may succeed in more cases than before; for example, assigning a numeric value 3.9 to an integer variable will now assign 4 rather than failing. If no assignment-grade cast is defined for the particular source and destination types, PL/pgSQL will fall back to its old I/O conversion behavior.
Original release occurrence ·
9.5.0/migration/003Allow characters in server command-line options to be escaped with a backslash Compatibility Migration
Allow characters in server command-line options to be escaped with a backslash (Andres Freund)
Formerly, spaces in the options string always separated options, so there was no way to include a space in an option value. Including a backslash in an option value now requires writing \\.
Original release occurrence ·
9.5.0/migration/004Change the default value of the GSSAPI include_realm parameter to 1, so that by default the realm is not removed from a GSS or SSPI principal name Compatibility Migration
Change the default value of the GSSAPI include_realm parameter to 1, so that by default the realm is not removed from a GSS or SSPI principal name (Stephen Frost)
Original release occurrence ·
9.5.0/migration/005Replace configuration parameter checkpoint_segments with min_wal_size and max_wal_size Compatibility Migration
Replace configuration parameter checkpoint_segments with min_wal_size and max_wal_size (Heikki Linnakangas)
If you previously adjusted checkpoint_segments, the following formula will give you an approximately equivalent setting:
max_wal_size = (3 * checkpoint_segments) * 16MB
Note that the default setting for max_wal_size is much higher than the default checkpoint_segments used to be, so adjusting it might no longer be necessary.
Original release occurrence ·
9.5.0/migration/006Control the Linux OOM killer via new environment variables PG_OOM_ADJUST_FILE and PG_OOM_ADJUST_VALUE, instead of compile-time options LINUX_OOM_SCORE_ADJ and LINUX_OOM_ADJ Compatibility Migration
Control the Linux OOM killer via new environment variables PG_OOM_ADJUST_FILE and PG_OOM_ADJUST_VALUE, instead of compile-time options LINUX_OOM_SCORE_ADJ and LINUX_OOM_ADJ (Gurjeet Singh)
Original release occurrence ·
9.5.0/migration/007Decommission server configuration parameter ssl_renegotiation_limit, which was deprecated in earlier releases Compatibility Migration
Decommission server configuration parameter ssl_renegotiation_limit, which was deprecated in earlier releases (Andres Freund)
While SSL renegotiation is a good idea in theory, it has caused enough bugs to be considered a net negative in practice, and it is due to be removed from future versions of the relevant standards. We have therefore removed support for it from PostgreSQL. The ssl_renegotiation_limit parameter still exists, but cannot be set to anything but zero (disabled). It's not documented anymore, either.
Original release occurrence ·
9.5.0/migration/008Remove server configuration parameter autocommit, which was already deprecated and non-operational Compatibility Migration
Remove server configuration parameter autocommit, which was already deprecated and non-operational (Tom Lane)
Original release occurrence ·
9.5.0/migration/009Remove the pg_authid catalog's rolcatupdate field, as it had no usefulness Compatibility Migration
Remove the pg_authid catalog's rolcatupdate field, as it had no usefulness (Adam Brightwell)
Original release occurrence ·
9.5.0/migration/010The pg_stat_replication system view's sent field is now NULL, not zero, when it has no valid value Compatibility Migration
The pg_stat_replication system view's sent field is now NULL, not zero, when it has no valid value (Magnus Hagander)
Original release occurrence ·
9.5.0/migration/011Allow json and jsonb array extraction operators to accept negative subscripts, which count from the end of JSON arrays Compatibility Migration
Allow json and jsonb array extraction operators to accept negative subscripts, which count from the end of JSON arrays (Peter Geoghegan, Andrew Dunstan)
Previously, these operators returned NULL for negative subscripts.
Original release occurrence ·
9.5.0/migration/012Add Block Range Indexes (BRIN) Features
Add Block Range Indexes (BRIN) (Álvaro Herrera)
BRIN indexes store only summary data (such as minimum and maximum values) for ranges of heap blocks. They are therefore very compact and cheap to update; but if the data is naturally clustered, they can still provide substantial speedup of searches.
Original release occurrence ·
9.5.0/changes/001Allow queries to perform accurate distance filtering of bounding-box-indexed objects (polygons, circles) using GiST indexes Features
Allow queries to perform accurate distance filtering of bounding-box-indexed objects (polygons, circles) using GiST indexes (Alexander Korotkov, Heikki Linnakangas)
Previously, to exploit such an index a subquery had to be used to select a large number of rows ordered by bounding-box distance, and the result then had to be filtered further with a more accurate distance calculation.
Original release occurrence ·
9.5.0/changes/002Allow GiST indexes to perform index-only scans Features
Allow GiST indexes to perform index-only scans (Anastasia Lubennikova, Heikki Linnakangas, Andreas Karlsson)
Original release occurrence ·
9.5.0/changes/003Add configuration parameter gin_pending_list_limit to control the size of GIN pending lists Features
Add configuration parameter gin_pending_list_limit to control the size of GIN pending lists (Fujii Masao)
This value can also be set on a per-index basis as an index storage parameter. Previously the pending-list size was controlled by work_mem, which was awkward because appropriate values for work_mem are often much too large for this purpose.
Original release occurrence ·
9.5.0/changes/004Issue a warning during the creation of hash indexes because they are not crash-safe Features
Issue a warning during the creation of hash indexes because they are not crash-safe (Bruce Momjian)
Original release occurrence ·
9.5.0/changes/005Improve the speed of sorting of varchar, text, and numeric fields via "abbreviated" keys Performance
Improve the speed of sorting of varchar, text, and numeric fields via "abbreviated" keys (Peter Geoghegan, Andrew Gierth, Robert Haas)
Original release occurrence ·
9.5.0/changes/006Extend the infrastructure that allows sorting to be performed by inlined, non-SQL-callable comparison functions to cover CREATE INDEX, REINDEX, and CLUSTER Performance
Extend the infrastructure that allows sorting to be performed by inlined, non-SQL-callable comparison functions to cover CREATE INDEX, REINDEX, and CLUSTER (Peter Geoghegan)
Original release occurrence ·
9.5.0/changes/007Improve performance of hash joins Performance
Improve performance of hash joins (Tomas Vondra, Robert Haas)
Original release occurrence ·
9.5.0/changes/008Improve concurrency of shared buffer replacement Performance
Improve concurrency of shared buffer replacement (Robert Haas, Amit Kapila, Andres Freund)
Original release occurrence ·
9.5.0/changes/009Reduce the number of page locks and pins during index scans Performance
Reduce the number of page locks and pins during index scans (Kevin Grittner)
The primary benefit of this is to allow index vacuums to be blocked less often.
Original release occurrence ·
9.5.0/changes/010Make per-backend tracking of buffer pins more memory-efficient Performance
Make per-backend tracking of buffer pins more memory-efficient (Andres Freund)
Original release occurrence ·
9.5.0/changes/011Improve lock scalability Performance
Improve lock scalability (Andres Freund)
This particularly addresses scalability problems when running on systems with multiple CPU sockets.
Original release occurrence ·
9.5.0/changes/012Allow the optimizer to remove unnecessary references to left-joined subqueries Performance
Allow the optimizer to remove unnecessary references to left-joined subqueries (David Rowley)
Original release occurrence ·
9.5.0/changes/013Allow pushdown of query restrictions into subqueries with window functions, where appropriate Performance
Allow pushdown of query restrictions into subqueries with window functions, where appropriate (David Rowley)
Original release occurrence ·
9.5.0/changes/014Allow a non-leakproof function to be pushed down into a security barrier view if the function does not receive any view output columns Performance
Allow a non-leakproof function to be pushed down into a security barrier view if the function does not receive any view output columns (Dean Rasheed)
Original release occurrence ·
9.5.0/changes/015Teach the planner to use statistics obtained from an expression index on a boolean-returning function, when a matching function call appears in WHERE Performance
Teach the planner to use statistics obtained from an expression index on a boolean-returning function, when a matching function call appears in WHERE (Tom Lane)
Original release occurrence ·
9.5.0/changes/016Make ANALYZE compute basic statistics (null fraction and average column width) even for columns whose data type lacks an equality function Performance
Make ANALYZE compute basic statistics (null fraction and average column width) even for columns whose data type lacks an equality function (Oleksandr Shulgin)
Original release occurrence ·
9.5.0/changes/017Speed up CRC (cyclic redundancy check) computations and switch to CRC-32C Performance
Speed up CRC (cyclic redundancy check) computations and switch to CRC-32C (Abhijit Menon-Sen, Heikki Linnakangas)
Original release occurrence ·
9.5.0/changes/018Improve bitmap index scan performance Performance
Improve bitmap index scan performance (Teodor Sigaev, Tom Lane)
Original release occurrence ·
9.5.0/changes/019Speed up CREATE INDEX by avoiding unnecessary memory copies Performance
Speed up CREATE INDEX by avoiding unnecessary memory copies (Robert Haas)
Original release occurrence ·
9.5.0/changes/020Increase the number of buffer mapping partitions Performance
Increase the number of buffer mapping partitions (Amit Kapila, Andres Freund, Robert Haas)
This improves performance for highly concurrent workloads.
Original release occurrence ·
9.5.0/changes/021Add per-table autovacuum logging control via new log_autovacuum_min_duration storage parameter Features
Add per-table autovacuum logging control via new log_autovacuum_min_duration storage parameter (Michael Paquier)
Original release occurrence ·
9.5.0/changes/022Add new configuration parameter cluster_name Features
Add new configuration parameter cluster_name (Thomas Munro)
This string, typically set in postgresql.conf, allows clients to identify the cluster. This name also appears in the process title of all server processes, allowing for easier identification of processes belonging to the same cluster.
Original release occurrence ·
9.5.0/changes/023Prevent non-superusers from changing log_disconnections on connection startup Features
Prevent non-superusers from changing log_disconnections on connection startup (Fujii Masao)
Original release occurrence ·
9.5.0/changes/024Check "Subject Alternative Names" in SSL server certificates, if present Features
Check "Subject Alternative Names" in SSL server certificates, if present (Alexey Klyukin)
When they are present, this replaces checks against the certificate's "Common Name".
Original release occurrence ·
9.5.0/changes/025Add system view pg_stat_ssl to report SSL connection information Features
Add system view pg_stat_ssl to report SSL connection information (Magnus Hagander)
Original release occurrence ·
9.5.0/changes/026Add libpq functions to return SSL information in an implementation-independent way Features
Add libpq functions to return SSL information in an implementation-independent way (Heikki Linnakangas)
While
PQgetssl()can still be used to call OpenSSL functions, it is now considered deprecated because future versions of libpq might support other SSL implementations. When possible, use the new functionsPQsslAttribute(),PQsslAttributeNames(), andPQsslInUse()to obtain SSL information in an SSL-implementation-independent way.Original release occurrence ·
9.5.0/changes/027Make libpq honor any OpenSSL thread callbacks Features
Make libpq honor any OpenSSL thread callbacks (Jan Urbanski)
Previously they were overwritten.
Original release occurrence ·
9.5.0/changes/028Replace configuration parameter checkpoint_segments with min_wal_size and max_wal_size Features
Replace configuration parameter checkpoint_segments with min_wal_size and max_wal_size (Heikki Linnakangas)
This change allows the allocation of a large number of WAL files without keeping them after they are no longer needed. Therefore the default for max_wal_size has been set to 1GB, much larger than the old default for checkpoint_segments. Also note that standby servers perform restartpoints to try to limit their WAL space consumption to max_wal_size; previously they did not pay any attention to checkpoint_segments.
Original release occurrence ·
9.5.0/changes/029Control the Linux OOM killer via new environment variables PG_OOM_ADJUST_FILE and PG_OOM_ADJUST_VALUE Features
Control the Linux OOM killer via new environment variables PG_OOM_ADJUST_FILE and PG_OOM_ADJUST_VALUE (Gurjeet Singh)
The previous OOM control infrastructure involved compile-time options LINUX_OOM_SCORE_ADJ and LINUX_OOM_ADJ, which are no longer supported. The new behavior is available in all builds.
Original release occurrence ·
9.5.0/changes/030Allow recording of transaction commit time stamps when configuration parameter track_commit_timestamp is enabled Features
Allow recording of transaction commit time stamps when configuration parameter track_commit_timestamp is enabled (Álvaro Herrera, Petr Jelínek)
Time stamp information can be accessed using functions
pg_xact_commit_timestamp()andpg_last_committed_xact().Original release occurrence ·
9.5.0/changes/031Allow local_preload_libraries to be set by ALTER ROLE SET Features
Allow local_preload_libraries to be set by ALTER ROLE SET (Peter Eisentraut, Kyotaro Horiguchi)
Original release occurrence ·
9.5.0/changes/032Allow autovacuum workers to respond to configuration parameter changes during a run Features
Allow autovacuum workers to respond to configuration parameter changes during a run (Michael Paquier)
Original release occurrence ·
9.5.0/changes/033Make configuration parameter debug_assertions read-only Features
Make configuration parameter debug_assertions read-only (Andres Freund)
This means that assertions can no longer be turned off if they were enabled at compile time, allowing for more efficient code optimization. This change also removes the postgres -A option.
Original release occurrence ·
9.5.0/changes/034Allow setting effective_io_concurrency on systems where it has no effect Features
Allow setting effective_io_concurrency on systems where it has no effect (Peter Eisentraut)
Original release occurrence ·
9.5.0/changes/035Add system view pg_file_settings to show the contents of the server's configuration files Features
Add system view pg_file_settings to show the contents of the server's configuration files (Sawada Masahiko)
Original release occurrence ·
9.5.0/changes/036Add pending_restart to the system view pg_settings to indicate a change has been made but will not take effect until a database restart Features
Add pending_restart to the system view pg_settings to indicate a change has been made but will not take effect until a database restart (Peter Eisentraut)
Original release occurrence ·
9.5.0/changes/037Allow ALTER SYSTEM values to be reset with ALTER SYSTEM RESET Features
Allow ALTER SYSTEM values to be reset with ALTER SYSTEM RESET (Vik Fearing)
This command removes the specified setting from postgresql.auto.conf.
Original release occurrence ·
9.5.0/changes/038Create mechanisms for tracking the progress of replication, including methods for identifying the origin of individual changes during logical replication Features
Create mechanisms for tracking the progress of replication, including methods for identifying the origin of individual changes during logical replication (Andres Freund)
This is helpful when implementing replication solutions.
Original release occurrence ·
9.5.0/changes/039Rework truncation of the multixact commit log to be properly WAL-logged Features
Rework truncation of the multixact commit log to be properly WAL-logged (Andres Freund)
This makes things substantially simpler and more robust.
Original release occurrence ·
9.5.0/changes/040Add recovery.conf parameter recovery_target_action to control post-recovery activity Features
Add recovery.conf parameter recovery_target_action to control post-recovery activity (Petr Jelínek)
This replaces the old parameter pause_at_recovery_target.
Original release occurrence ·
9.5.0/changes/041Add new archive_mode value always to allow standbys to always archive received WAL files Features
Add new archive_mode value always to allow standbys to always archive received WAL files (Fujii Masao)
Original release occurrence ·
9.5.0/changes/042Add configuration parameter wal_retrieve_retry_interval to control WAL read retry after failure Features
Add configuration parameter wal_retrieve_retry_interval to control WAL read retry after failure (Alexey Vasiliev, Michael Paquier)
This is particularly helpful for warm standbys.
Original release occurrence ·
9.5.0/changes/043Allow compression of full-page images stored in WAL Features
Allow compression of full-page images stored in WAL (Rahila Syed, Michael Paquier)
This feature reduces WAL volume, at the cost of more CPU time spent on WAL logging and WAL replay. It is controlled by a new configuration parameter wal_compression, which currently is off by default.
Original release occurrence ·
9.5.0/changes/044Archive WAL files with suffix .partial during standby promotion Features
Archive WAL files with suffix .partial during standby promotion (Heikki Linnakangas)
Original release occurrence ·
9.5.0/changes/045Add configuration parameter log_replication_commands to log replication commands Features
Add configuration parameter log_replication_commands to log replication commands (Fujii Masao)
By default, replication commands, e.g., IDENTIFY_SYSTEM, are not logged, even when log_statement is set to all.
Original release occurrence ·
9.5.0/changes/046Report the processes holding replication slots in pg_replication_slots Features
Report the processes holding replication slots in pg_replication_slots (Craig Ringer)
The new output column is active_pid.
Original release occurrence ·
9.5.0/changes/047Allow recovery.conf's primary_conninfo setting to use connection URIs, e.g., postgres:// Features
Allow recovery.conf's primary_conninfo setting to use connection URIs, e.g., postgres:// (Alexander Shulgin)
Original release occurrence ·
9.5.0/changes/048Allow INSERTs that would generate constraint conflicts to be turned into UPDATEs or ignored Features
Allow INSERTs that would generate constraint conflicts to be turned into UPDATEs or ignored (Peter Geoghegan, Heikki Linnakangas, Andres Freund)
The syntax is INSERT ... ON CONFLICT DO NOTHING/UPDATE. This is the Postgres implementation of the popular UPSERT command.
Original release occurrence ·
9.5.0/changes/049Add GROUP BY analysis features GROUPING SETS, CUBE and ROLLUP Features
Add GROUP BY analysis features GROUPING SETS, CUBE and ROLLUP (Andrew Gierth, Atri Sharma)
Original release occurrence ·
9.5.0/changes/050Allow setting multiple target columns in an UPDATE from the result of a single sub-SELECT Features
Allow setting multiple target columns in an UPDATE from the result of a single sub-SELECT (Tom Lane)
This is accomplished using the syntax UPDATE tab SET (col1, col2, ...) = (SELECT ...).
Original release occurrence ·
9.5.0/changes/051Add SELECT option SKIP LOCKED to skip locked rows Features
Add SELECT option SKIP LOCKED to skip locked rows (Thomas Munro)
This does not throw an error for locked rows like NOWAIT does.
Original release occurrence ·
9.5.0/changes/052Add SELECT option TABLESAMPLE to return a subset of a table Features
Add SELECT option TABLESAMPLE to return a subset of a table (Petr Jelínek)
This feature supports the SQL-standard table sampling methods. In addition, there are provisions for user-defined table sampling methods.
Original release occurrence ·
9.5.0/changes/053Suggest possible matches for mistyped column names Features
Suggest possible matches for mistyped column names (Peter Geoghegan, Robert Haas)
Original release occurrence ·
9.5.0/changes/054Add more details about sort ordering in EXPLAIN output Features
Add more details about sort ordering in EXPLAIN output (Marius Timmer, Lukas Kreft, Arne Scheffer)
Details include COLLATE, DESC, USING, and NULLS FIRST/LAST.
Original release occurrence ·
9.5.0/changes/055Make VACUUM log the number of pages skipped due to pins Features
Make VACUUM log the number of pages skipped due to pins (Jim Nasby)
Original release occurrence ·
9.5.0/changes/056Make TRUNCATE properly update the pg_stat* tuple counters Features
Make TRUNCATE properly update the pg_stat* tuple counters (Alexander Shulgin)
Original release occurrence ·
9.5.0/changes/057Allow REINDEX to reindex an entire schema using the SCHEMA option Features
Allow REINDEX to reindex an entire schema using the SCHEMA option (Sawada Masahiko)
Original release occurrence ·
9.5.0/changes/058Add VERBOSE option to REINDEX Features
Add VERBOSE option to REINDEX (Sawada Masahiko)
Original release occurrence ·
9.5.0/changes/059Prevent REINDEX DATABASE and SCHEMA from outputting object names, unless VERBOSE is used Features
Prevent REINDEX DATABASE and SCHEMA from outputting object names, unless VERBOSE is used (Simon Riggs)
Original release occurrence ·
9.5.0/changes/060Remove obsolete FORCE option from REINDEX Features
Remove obsolete FORCE option from REINDEX (Fujii Masao)
Original release occurrence ·
9.5.0/changes/061Add row-level security control Features
Add row-level security control (Craig Ringer, KaiGai Kohei, Adam Brightwell, Dean Rasheed, Stephen Frost)
This feature allows row-by-row control over which users can add, modify, or even see rows in a table. This is controlled by new commands CREATE/ALTER/DROP POLICY and ALTER TABLE ... ENABLE/DISABLE ROW SECURITY.
Original release occurrence ·
9.5.0/changes/062Allow changing of the WAL logging status of a table after creation with ALTER TABLE ... SET LOGGED / UNLOGGED Features
Allow changing of the WAL logging status of a table after creation with ALTER TABLE ... SET LOGGED / UNLOGGED (Fabrízio de Royes Mello)
Original release occurrence ·
9.5.0/changes/063Add IF NOT EXISTS clause to CREATE TABLE AS, CREATE INDEX, CREATE SEQUENCE, and CREATE MATERIALIZED VIEW Features
Add IF NOT EXISTS clause to CREATE TABLE AS, CREATE INDEX, CREATE SEQUENCE, and CREATE MATERIALIZED VIEW (Fabrízio de Royes Mello)
Original release occurrence ·
9.5.0/changes/064Add support for IF EXISTS to ALTER TABLE ... RENAME CONSTRAINT Features
Add support for IF EXISTS to ALTER TABLE ... RENAME CONSTRAINT (Bruce Momjian)
Original release occurrence ·
9.5.0/changes/065Allow some DDL commands to accept CURRENT_USER or SESSION_USER, meaning the current user or session user, in place of a specific user name Features
Allow some DDL commands to accept CURRENT_USER or SESSION_USER, meaning the current user or session user, in place of a specific user name (Kyotaro Horiguchi, Álvaro Herrera)
This feature is now supported in ALTER USER, ALTER GROUP, ALTER ROLE, GRANT, and ALTER object OWNER TO commands.
Original release occurrence ·
9.5.0/changes/066Support comments on domain constraints Features
Support comments on domain constraints (Álvaro Herrera)
Original release occurrence ·
9.5.0/changes/067Reduce lock levels of some create and alter trigger and foreign key commands Features
Reduce lock levels of some create and alter trigger and foreign key commands (Simon Riggs, Andreas Karlsson)
Original release occurrence ·
9.5.0/changes/068Allow LOCK TABLE ... ROW EXCLUSIVE MODE for those with INSERT privileges on the target table Features
Allow LOCK TABLE ... ROW EXCLUSIVE MODE for those with INSERT privileges on the target table (Stephen Frost)
Previously this command required UPDATE, DELETE, or TRUNCATE privileges.
Original release occurrence ·
9.5.0/changes/069Apply table and domain CHECK constraints in order by name Features
Apply table and domain CHECK constraints in order by name (Tom Lane)
The previous ordering was indeterminate.
Original release occurrence ·
9.5.0/changes/070Allow CREATE/ALTER DATABASE to manipulate datistemplate and datallowconn Features
Allow CREATE/ALTER DATABASE to manipulate datistemplate and datallowconn (Vik Fearing)
This allows these per-database settings to be changed without manually modifying the pg_database system catalog.
Original release occurrence ·
9.5.0/changes/071Add support for IMPORT FOREIGN SCHEMA Features
Add support for IMPORT FOREIGN SCHEMA (Ronan Dunklau, Michael Paquier, Tom Lane)
This command allows automatic creation of local foreign tables that match the structure of existing tables on a remote server.
Original release occurrence ·
9.5.0/changes/072Allow CHECK constraints to be placed on foreign tables Features
Allow CHECK constraints to be placed on foreign tables (Shigeru Hanada, Etsuro Fujita)
Such constraints are assumed to be enforced on the remote server, and are not enforced locally. However, they are assumed to hold for purposes of query optimization, such as constraint exclusion.
Original release occurrence ·
9.5.0/changes/073Allow foreign tables to participate in inheritance Features
Allow foreign tables to participate in inheritance (Shigeru Hanada, Etsuro Fujita)
To let this work naturally, foreign tables are now allowed to have check constraints marked as not valid, and to set storage and OID characteristics, even though these operations are effectively no-ops for a foreign table.
Original release occurrence ·
9.5.0/changes/074Allow foreign data wrappers and custom scans to implement join pushdown Features
Allow foreign data wrappers and custom scans to implement join pushdown (KaiGai Kohei)
Original release occurrence ·
9.5.0/changes/075Whenever a ddl_command_end event trigger is installed, capture details of DDL activity for it to inspect Features
Whenever a ddl_command_end event trigger is installed, capture details of DDL activity for it to inspect (Álvaro Herrera)
This information is available through a set-returning function
pg_event_trigger_ddl_commands(), or by inspection of C data structures if that function doesn't provide enough detail.Original release occurrence ·
9.5.0/changes/076Allow event triggers on table rewrites caused by ALTER TABLE Features
Allow event triggers on table rewrites caused by ALTER TABLE (Dimitri Fontaine)
Original release occurrence ·
9.5.0/changes/077Add event trigger support for database-level COMMENT, SECURITY LABEL, and GRANT/REVOKE Features
Add event trigger support for database-level COMMENT, SECURITY LABEL, and GRANT/REVOKE (Álvaro Herrera)
Original release occurrence ·
9.5.0/changes/078Add columns to the output of pg_event_trigger_dropped_objects Features
Add columns to the output of
pg_event_trigger_dropped_objects(Álvaro Herrera)This allows simpler processing of delete operations.
Original release occurrence ·
9.5.0/changes/079Allow the xml data type to accept empty or all-whitespace content values Features
Allow the xml data type to accept empty or all-whitespace content values (Peter Eisentraut)
This is required by the SQL/XML specification.
Original release occurrence ·
9.5.0/changes/080Allow macaddr input using the format xxxx-xxxx-xxxx Features
Allow macaddr input using the format xxxx-xxxx-xxxx (Herwin Weststrate)
Original release occurrence ·
9.5.0/changes/081Disallow non-SQL-standard syntax for interval with both precision and field specifications Features
Disallow non-SQL-standard syntax for interval with both precision and field specifications (Bruce Momjian)
Per the standard, such type specifications should be written as, for example, INTERVAL MINUTE TO SECOND(2). PostgreSQL formerly allowed this to be written as INTERVAL(2) MINUTE TO SECOND, but it must now be written in the standard way.
Original release occurrence ·
9.5.0/changes/082Add selectivity estimators for inet/cidr operators and improve estimators for text search functions Features
Add selectivity estimators for inet/cidr operators and improve estimators for text search functions (Emre Hasegeli, Tom Lane)
Original release occurrence ·
9.5.0/changes/083Add data types regrole and regnamespace to simplify entering and pretty-printing the OID of a role or namespace Features
Add data types regrole and regnamespace to simplify entering and pretty-printing the OID of a role or namespace (Kyotaro Horiguchi)
Original release occurrence ·
9.5.0/changes/084Add jsonb functions jsonb_set() and jsonb_pretty() Features
Add jsonb functions
jsonb_set()andjsonb_pretty()(Dmitry Dolgov, Andrew Dunstan, Petr Jelínek)Original release occurrence ·
9.5.0/changes/085Add jsonb generator functions to_jsonb(), jsonb_object(), jsonb_build_object(), jsonb_build_array(), jsonb_agg(), and jsonb_object_agg() Features
Add jsonb generator functions
to_jsonb(),jsonb_object(),jsonb_build_object(),jsonb_build_array(),jsonb_agg(), andjsonb_object_agg()(Andrew Dunstan)Equivalent functions already existed for type json.
Original release occurrence ·
9.5.0/changes/086Reduce casting requirements to/from json and jsonb Features
Original release occurrence ·
9.5.0/changes/087Allow text, text array, and integer values to be subtracted from jsonb documents Features
Allow text, text array, and integer values to be subtracted from jsonb documents (Dmitry Dolgov, Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/088Add jsonb || operator Features
Add jsonb || operator (Dmitry Dolgov, Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/089Add json_strip_nulls() and jsonb_strip_nulls() functions to remove JSON null values from documents Features
Add
json_strip_nulls()andjsonb_strip_nulls()functions to remove JSON null values from documents (Andrew Dunstan)Original release occurrence ·
9.5.0/changes/090Add generate_series() for numeric values Features
Add
generate_series()for numeric values (Plato Malugin)Original release occurrence ·
9.5.0/changes/091Allow array_agg() and ARRAY() to take arrays as inputs Features
Allow
array_agg()andARRAY()to take arrays as inputs (Ali Akbar, Tom Lane)Original release occurrence ·
9.5.0/changes/092Add functions array_position() and array_positions() to return subscripts of array values Features
Add functions
array_position()andarray_positions()to return subscripts of array values (Pavel Stehule)Original release occurrence ·
9.5.0/changes/093Add a point-to-polygon distance operator <-> Features
Add a point-to-polygon distance operator <-> (Alexander Korotkov)
Original release occurrence ·
9.5.0/changes/094Allow multibyte characters as escapes in SIMILAR TO and SUBSTRING Features
Allow multibyte characters as escapes in SIMILAR TO and SUBSTRING (Jeff Davis)
Previously, only a single-byte character was allowed as an escape.
Original release occurrence ·
9.5.0/changes/095Add a width_bucket() variant that supports any sortable data type and non-uniform bucket widths Features
Add a
width_bucket()variant that supports any sortable data type and non-uniform bucket widths (Petr Jelínek)Original release occurrence ·
9.5.0/changes/096Add an optional missing_ok argument to pg_read_file() and related functions Features
Add an optional missing_ok argument to
pg_read_file()and related functions (Michael Paquier, Heikki Linnakangas)Original release occurrence ·
9.5.0/changes/097Allow => to specify named parameters in function calls Features
Allow => to specify named parameters in function calls (Pavel Stehule)
Previously only := could be used. This requires removing the possibility for => to be a user-defined operator. Creation of user-defined => operators has been issuing warnings since PostgreSQL 9.0.
Original release occurrence ·
9.5.0/changes/098Add POSIX-compliant rounding for platforms that use PostgreSQL-supplied rounding functions Features
Add POSIX-compliant rounding for platforms that use PostgreSQL-supplied rounding functions (Pedro Gimeno Fortea)
Original release occurrence ·
9.5.0/changes/099Add function pg_get_object_address() to return OIDs that uniquely identify an object, and function pg_identify_object_as_address() to return object information based on OIDs Features
Add function
pg_get_object_address()to return OIDs that uniquely identify an object, and functionpg_identify_object_as_address()to return object information based on OIDs (Álvaro Herrera)Original release occurrence ·
9.5.0/changes/100Loosen security checks for viewing queries in pg_stat_activity, executing pg_cancel_backend(), and executing pg_terminate_backend() Features
Loosen security checks for viewing queries in pg_stat_activity, executing
pg_cancel_backend(), and executingpg_terminate_backend()(Stephen Frost)Previously, only the specific role owning the target session could perform these operations; now membership in that role is sufficient.
Original release occurrence ·
9.5.0/changes/101Add pg_stat_get_snapshot_timestamp() to output the time stamp of the statistics snapshot Features
Add
pg_stat_get_snapshot_timestamp()to output the time stamp of the statistics snapshot (Matt Kelly)This represents the last time the snapshot file was written to the file system.
Original release occurrence ·
9.5.0/changes/102Add mxid_age() to compute multi-xid age Features
Add
mxid_age()to compute multi-xid age (Bruce Momjian)Original release occurrence ·
9.5.0/changes/103Add min()/max() aggregates for inet/cidr data types Features
Original release occurrence ·
9.5.0/changes/104Use 128-bit integers, where supported, as accumulators for some aggregate functions Features
Use 128-bit integers, where supported, as accumulators for some aggregate functions (Andreas Karlsson)
Original release occurrence ·
9.5.0/changes/105Improve support for composite types in PL/Python Features
Improve support for composite types in PL/Python (Ed Behn, Ronan Dunklau)
This allows PL/Python functions to return arrays of composite types.
Original release occurrence ·
9.5.0/changes/106Reduce lossiness of PL/Python floating-point value conversions Features
Reduce lossiness of PL/Python floating-point value conversions (Marko Kreen)
Original release occurrence ·
9.5.0/changes/107Allow specification of conversion routines between SQL data types and data types of procedural languages Features
Allow specification of conversion routines between SQL data types and data types of procedural languages (Peter Eisentraut)
This change adds new commands CREATE/DROP TRANSFORM. This also adds optional transformations between the hstore and ltree types to/from PL/Perl and PL/Python.
Original release occurrence ·
9.5.0/changes/108Improve PL/pgSQL array performance Performance
Improve PL/pgSQL array performance (Tom Lane)
Original release occurrence ·
9.5.0/changes/109Add an ASSERT statement in PL/pgSQL Features
Add an ASSERT statement in PL/pgSQL (Pavel Stehule)
Original release occurrence ·
9.5.0/changes/110Allow more PL/pgSQL keywords to be used as identifiers Features
Allow more PL/pgSQL keywords to be used as identifiers (Tom Lane)
Original release occurrence ·
9.5.0/changes/111Move pg_archivecleanup, pg_test_fsync, pg_test_timing, and pg_xlogdump from contrib to src/bin Features
Move pg_archivecleanup, pg_test_fsync, pg_test_timing, and pg_xlogdump from contrib to src/bin (Peter Eisentraut)
This should result in these programs being installed by default in most installations.
Original release occurrence ·
9.5.0/changes/112Add pg_rewind, which allows re-synchronizing a master server after failback Features
Add pg_rewind, which allows re-synchronizing a master server after failback (Heikki Linnakangas)
Original release occurrence ·
9.5.0/changes/113Allow pg_receivexlog to manage physical replication slots Features
Allow pg_receivexlog to manage physical replication slots (Michael Paquier)
This is controlled via new --create-slot and --drop-slot options.
Original release occurrence ·
9.5.0/changes/114Allow pg_receivexlog to synchronously flush WAL to storage using new --synchronous option Features
Allow pg_receivexlog to synchronously flush WAL to storage using new --synchronous option (Furuya Osamu, Fujii Masao)
Without this, WAL files are fsync'ed only on close.
Original release occurrence ·
9.5.0/changes/115Allow vacuumdb to vacuum in parallel using new --jobs option Features
Allow vacuumdb to vacuum in parallel using new --jobs option (Dilip Kumar)
Original release occurrence ·
9.5.0/changes/116In vacuumdb, do not prompt for the same password repeatedly when multiple connections are necessary Features
In vacuumdb, do not prompt for the same password repeatedly when multiple connections are necessary (Haribabu Kommi, Michael Paquier)
Original release occurrence ·
9.5.0/changes/117Add --verbose option to reindexdb Features
Add --verbose option to reindexdb (Sawada Masahiko)
Original release occurrence ·
9.5.0/changes/118Make pg_basebackup use a tablespace mapping file when using tar format, to support symbolic links and file paths of 100+ characters in length on MS Windows Features
Make pg_basebackup use a tablespace mapping file when using tar format, to support symbolic links and file paths of 100+ characters in length on MS Windows (Amit Kapila)
Original release occurrence ·
9.5.0/changes/119Add pg_xlogdump option --stats to display summary statistics Features
Add pg_xlogdump option --stats to display summary statistics (Abhijit Menon-Sen)
Original release occurrence ·
9.5.0/changes/120Allow psql to produce AsciiDoc output Features
Allow psql to produce AsciiDoc output (Szymon Guz)
Original release occurrence ·
9.5.0/changes/121Add an errors mode that displays only failed commands to psql's ECHO variable Features
Add an errors mode that displays only failed commands to psql's ECHO variable (Pavel Stehule)
This behavior can also be selected with psql's -b option.
Original release occurrence ·
9.5.0/changes/122Provide separate column, header, and border linestyle control in psql's unicode linestyle Features
Provide separate column, header, and border linestyle control in psql's unicode linestyle (Pavel Stehule)
Single or double lines are supported; the default is single.
Original release occurrence ·
9.5.0/changes/123Add new option %l in psql's PROMPT variables to display the current multiline statement line number Features
Add new option %l in psql's PROMPT variables to display the current multiline statement line number (Sawada Masahiko)
Original release occurrence ·
9.5.0/changes/124Add \pset option pager_min_lines to control pager invocation Features
Add \pset option pager_min_lines to control pager invocation (Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/125Improve psql line counting used when deciding to invoke the pager Features
Improve psql line counting used when deciding to invoke the pager (Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/126psql now fails if the file specified by an --output or --log-file switch cannot be written Features
psql now fails if the file specified by an --output or --log-file switch cannot be written (Tom Lane, Daniel Vérité)
Previously, it effectively ignored the switch in such cases.
Original release occurrence ·
9.5.0/changes/127Add psql tab completion when setting the search_path variable Features
Add psql tab completion when setting the search_path variable (Jeff Janes)
Currently only the first schema can be tab-completed.
Original release occurrence ·
9.5.0/changes/128Improve psql's tab completion for triggers and rules Features
Improve psql's tab completion for triggers and rules (Andreas Karlsson)
Original release occurrence ·
9.5.0/changes/129Add psql \? help sections variables and options Features
Add psql \? help sections variables and options (Pavel Stehule)
\? variables shows psql's special variables and \? options shows the command-line options. \? commands shows the meta-commands, which is the traditional output and remains the default. These help displays can also be obtained with the command-line option --help=section.
Original release occurrence ·
9.5.0/changes/130Show tablespace size in psql's \db+ Features
Show tablespace size in psql's \db+ (Fabrízio de Royes Mello)
Original release occurrence ·
9.5.0/changes/131Show data type owners in psql's \dT+ Features
Show data type owners in psql's \dT+ (Magnus Hagander)
Original release occurrence ·
9.5.0/changes/132Allow psql's \watch to output \timing information Features
Allow psql's \watch to output \timing information (Fujii Masao)
Also prevent --echo-hidden from echoing \watch queries, since that is generally unwanted.
Original release occurrence ·
9.5.0/changes/133Make psql's \sf and \ef commands honor ECHO_HIDDEN Features
Make psql's \sf and \ef commands honor ECHO_HIDDEN (Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/134Improve psql tab completion for \set, \unset, and :variable names Features
Improve psql tab completion for \set, \unset, and :variable names (Pavel Stehule)
Original release occurrence ·
9.5.0/changes/135Allow tab completion of role names in psql \c commands Features
Allow tab completion of role names in psql \c commands (Ian Barwick)
Original release occurrence ·
9.5.0/changes/136Allow pg_dump to share a snapshot taken by another session using --snapshot Features
Allow pg_dump to share a snapshot taken by another session using --snapshot (Simon Riggs, Michael Paquier)
The remote snapshot must have been exported by
pg_export_snapshot()or logical replication slot creation. This can be used to share a consistent snapshot across multiple pg_dump processes.Original release occurrence ·
9.5.0/changes/137Support table sizes exceeding 8GB in tar archive format Features
Support table sizes exceeding 8GB in tar archive format (Tom Lane)
The POSIX standard for tar format does not allow elements of a tar archive to exceed 8GB, but most modern implementations of tar support an extension that does allow it. Use the extension format when necessary, rather than failing.
Original release occurrence ·
9.5.0/changes/138Make pg_dump always print the server and pg_dump versions Features
Make pg_dump always print the server and pg_dump versions (Jing Wang)
Previously, version information was only printed in --verbose mode.
Original release occurrence ·
9.5.0/changes/139Remove the long-ignored -i/--ignore-version option from pg_dump, pg_dumpall, and pg_restore Features
Remove the long-ignored -i/--ignore-version option from pg_dump, pg_dumpall, and pg_restore (Fujii Masao)
Original release occurrence ·
9.5.0/changes/140Support multiple pg_ctl -o options, concatenating their values Features
Support multiple pg_ctl -o options, concatenating their values (Bruce Momjian)
Original release occurrence ·
9.5.0/changes/141Allow control of pg_ctl's event source logging on MS Windows Features
Allow control of pg_ctl's event source logging on MS Windows (MauMau)
This only controls pg_ctl, not the server, which has separate settings in postgresql.conf.
Original release occurrence ·
9.5.0/changes/142If the server's listen address is set to a wildcard value (0.0.0.0 in IPv4 or :: in IPv6), connect via the loopback address rather than trying to use the wildcard address literally Features
If the server's listen address is set to a wildcard value (0.0.0.0 in IPv4 or :: in IPv6), connect via the loopback address rather than trying to use the wildcard address literally (Kondo Yuta)
This fix primarily affects Windows, since on other platforms pg_ctl will prefer to use a Unix-domain socket.
Original release occurrence ·
9.5.0/changes/143Move pg_upgrade from contrib to src/bin Features
Move pg_upgrade from contrib to src/bin (Peter Eisentraut)
In connection with this change, the functionality previously provided by the pg_upgrade_support module has been moved into the core server.
Original release occurrence ·
9.5.0/changes/144Support multiple pg_upgrade -o/-O options, concatenating their values Features
Support multiple pg_upgrade -o/-O options, concatenating their values (Bruce Momjian)
Original release occurrence ·
9.5.0/changes/145Improve database collation comparisons in pg_upgrade Features
Improve database collation comparisons in pg_upgrade (Heikki Linnakangas)
Original release occurrence ·
9.5.0/changes/146Remove support for upgrading from 8.3 clusters Features
Remove support for upgrading from 8.3 clusters (Bruce Momjian)
Original release occurrence ·
9.5.0/changes/147Move pgbench from contrib to src/bin Features
Move pgbench from contrib to src/bin (Peter Eisentraut)
Original release occurrence ·
9.5.0/changes/148Fix calculation of TPS number "excluding connections establishing" Bug fixes
Fix calculation of TPS number "excluding connections establishing" (Tatsuo Ishii, Fabien Coelho)
The overhead for connection establishment was miscalculated whenever the number of pgbench threads was less than the number of client connections. Although this is clearly a bug, we won't back-patch it into pre-9.5 branches since it makes TPS numbers not comparable to previous results.
Original release occurrence ·
9.5.0/changes/149Allow counting of pgbench transactions that take over a specified amount of time Features
Allow counting of pgbench transactions that take over a specified amount of time (Fabien Coelho)
This is controlled by a new --latency-limit option.
Original release occurrence ·
9.5.0/changes/150Allow pgbench to generate Gaussian/exponential distributions using \setrandom Features
Allow pgbench to generate Gaussian/exponential distributions using \setrandom (Kondo Mitsumasa, Fabien Coelho)
Original release occurrence ·
9.5.0/changes/151Allow pgbench's \set command to handle arithmetic expressions containing more than one operator, and add % (modulo) to the set of operators it supports Features
Allow pgbench's \set command to handle arithmetic expressions containing more than one operator, and add % (modulo) to the set of operators it supports (Robert Haas, Fabien Coelho)
Original release occurrence ·
9.5.0/changes/152Simplify WAL record format Features
Simplify WAL record format (Heikki Linnakangas)
This allows external tools to more easily track what blocks are modified.
Original release occurrence ·
9.5.0/changes/153Improve the representation of transaction commit and abort WAL records Features
Improve the representation of transaction commit and abort WAL records (Andres Freund)
Original release occurrence ·
9.5.0/changes/154Add atomic memory operations API Features
Add atomic memory operations API (Andres Freund)
Original release occurrence ·
9.5.0/changes/155Allow custom path and scan methods Features
Allow custom path and scan methods (KaiGai Kohei, Tom Lane)
This allows extensions greater control over the optimizer and executor.
Original release occurrence ·
9.5.0/changes/156Allow foreign data wrappers to do post-filter locking Features
Allow foreign data wrappers to do post-filter locking (Etsuro Fujita)
Original release occurrence ·
9.5.0/changes/157Foreign tables can now take part in INSERT ... ON CONFLICT DO NOTHING queries Features
Foreign tables can now take part in INSERT ... ON CONFLICT DO NOTHING queries (Peter Geoghegan, Heikki Linnakangas, Andres Freund)
Foreign data wrappers must be modified to handle this. INSERT ... ON CONFLICT DO UPDATE is not supported on foreign tables.
Original release occurrence ·
9.5.0/changes/158Improve hash_create()'s API for selecting simple-binary-key hash functions Features
Improve
hash_create()'s API for selecting simple-binary-key hash functions (Teodor Sigaev, Tom Lane)Original release occurrence ·
9.5.0/changes/159Improve parallel execution infrastructure Features
Improve parallel execution infrastructure (Robert Haas, Amit Kapila, Noah Misch, Rushabh Lathia, Jeevan Chalke)
Original release occurrence ·
9.5.0/changes/160Remove Alpha (CPU) and Tru64 (OS) ports Features
Remove Alpha (CPU) and Tru64 (OS) ports (Andres Freund)
Original release occurrence ·
9.5.0/changes/161Remove swap-byte-based spinlock implementation for ARMv5 and earlier CPUs Features
Remove swap-byte-based spinlock implementation for ARMv5 and earlier CPUs (Robert Haas)
ARMv5's weak memory ordering made this locking implementation unsafe. Spinlock support is still possible on newer gcc implementations with atomics support.
Original release occurrence ·
9.5.0/changes/162Generate an error when excessively long (100+ character) file paths are written to tar files Features
Generate an error when excessively long (100+ character) file paths are written to tar files (Peter Eisentraut)
Tar does not support such overly-long paths.
Original release occurrence ·
9.5.0/changes/163Change index operator class for columns pg_seclabel.provider and pg_shseclabel.provider to be text_pattern_ops Features
Change index operator class for columns pg_seclabel.provider and pg_shseclabel.provider to be text_pattern_ops (Tom Lane)
This avoids possible problems with these indexes when different databases of a cluster have different default collations.
Original release occurrence ·
9.5.0/changes/164Change the spinlock primitives to function as compiler barriers Features
Change the spinlock primitives to function as compiler barriers (Robert Haas)
Original release occurrence ·
9.5.0/changes/165Allow higher-precision time stamp resolution on Windows 8, Windows Server 2012, and later Windows systems Features
Allow higher-precision time stamp resolution on Windows 8, Windows Server 2012, and later Windows systems (Craig Ringer)
Original release occurrence ·
9.5.0/changes/166Install shared libraries to bin in MS Windows Features
Install shared libraries to bin in MS Windows (Peter Eisentraut, Michael Paquier)
Original release occurrence ·
9.5.0/changes/167Install src/test/modules together with contrib on MSVC builds Features
Install src/test/modules together with contrib on MSVC builds (Michael Paquier)
Original release occurrence ·
9.5.0/changes/168Allow configure's --with-extra-version option to be honored by the MSVC build Features
Allow configure's --with-extra-version option to be honored by the MSVC build (Michael Paquier)
Original release occurrence ·
9.5.0/changes/169Pass PGFILEDESC into MSVC contrib builds Features
Pass PGFILEDESC into MSVC contrib builds (Michael Paquier)
Original release occurrence ·
9.5.0/changes/170Add icons to all MSVC-built binaries and version information to all MS Windows binaries Features
Add icons to all MSVC-built binaries and version information to all MS Windows binaries (Noah Misch)
MinGW already had such icons.
Original release occurrence ·
9.5.0/changes/171Add optional-argument support to the internal getopt_long() implementation Features
Add optional-argument support to the internal
getopt_long()implementation (Michael Paquier, Andres Freund)This is used by the MSVC build.
Original release occurrence ·
9.5.0/changes/172Add statistics for minimum, maximum, mean, and standard deviation times to pg_stat_statements Features
Add statistics for minimum, maximum, mean, and standard deviation times to pg_stat_statements (Mitsumasa Kondo, Andrew Dunstan)
Original release occurrence ·
9.5.0/changes/173Add pgcrypto function pgp_armor_headers() to extract PGP armor headers Features
Add pgcrypto function
pgp_armor_headers()to extract PGP armor headers (Marko Tiikkaja, Heikki Linnakangas)Original release occurrence ·
9.5.0/changes/174Allow empty replacement strings in unaccent Features
Allow empty replacement strings in unaccent (Mohammad Alhashash)
This is useful in languages where diacritic signs are represented as separate characters.
Original release occurrence ·
9.5.0/changes/175Allow multicharacter source strings in unaccent Features
Allow multicharacter source strings in unaccent (Tom Lane)
This could be useful in languages where diacritic signs are represented as separate characters. It also allows more complex unaccent dictionaries.
Original release occurrence ·
9.5.0/changes/176Add contrib modules tsm_system_rows and tsm_system_time to allow additional table sampling methods Features
Add contrib modules tsm_system_rows and tsm_system_time to allow additional table sampling methods (Petr Jelínek)
Original release occurrence ·
9.5.0/changes/177Add GIN index inspection functions to pageinspect Features
Add GIN index inspection functions to pageinspect (Heikki Linnakangas, Peter Geoghegan, Michael Paquier)
Original release occurrence ·
9.5.0/changes/178Add information about buffer pins to pg_buffercache display Features
Add information about buffer pins to pg_buffercache display (Andres Freund)
Original release occurrence ·
9.5.0/changes/179Allow pgstattuple to report approximate answers with less overhead using pgstattuple_approx() Features
Allow pgstattuple to report approximate answers with less overhead using
pgstattuple_approx()(Abhijit Menon-Sen)Original release occurrence ·
9.5.0/changes/180Move dummy_seclabel, test_shm_mq, test_parser, and worker_spi from contrib to src/test/modules Features
Move dummy_seclabel, test_shm_mq, test_parser, and worker_spi from contrib to src/test/modules (Álvaro Herrera)
These modules are only meant for server testing, so they do not need to be built or installed when packaging PostgreSQL.
Original release occurrence ·
9.5.0/changes/181
Security evidence
33 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 9.5.24. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 9.5.24. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 9.5.24. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 9.5.23. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
Fixed in this branch: 9.5.22. Component: packaging.
Official affected-branch entry: 9.5.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
Fixed in this branch: 9.5.20. Component: packaging.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
Fixed in this branch: 9.5.19. Component: packaging.
Official affected-branch entry: 9.5.
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 9.5.19. Component: packaging.
Official affected-branch entry: 9.5.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 9.5.19. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
Fixed in this branch: 9.5.17. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 9.5.17. Component: packaging.
Official affected-branch entry: 9.5.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 9.5.17. Component: packaging.
Official affected-branch entry: 9.5.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. CVSS 7.1
Fixed in this branch: 9.5.14. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Release-note mentions:
CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5
Fixed in this branch: 9.5.14. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
Fixed in this branch: 9.5.12. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7
Fixed in this branch: 9.5.11. Component: client.
Official affected-branch entry: 9.5.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7548 · lo_put() function ignores ACLs CVSS 3.1
Fixed in this branch: 9.5.8. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges CVSS 8.5
Fixed in this branch: 9.5.8. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7546 · empty password accepted in some authentication methods CVSS 8.1
Fixed in this branch: 9.5.8. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords CVSS 8.5
Fixed in this branch: 9.5.7. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable CVSS 8.1
Fixed in this branch: 9.5.7. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
Fixed in this branch: 9.5.7. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVSS 3.1
Fixed in this branch: 9.5.10. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3
Fixed in this branch: 9.5.10. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4
Fixed in this branch: 9.5.10. Component: contrib module.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2016-7048 · Interactive installer downloads software over plain HTTP, then executes it CVSS 7.5
Fixed in this branch: 9.5.5. Component: packaging.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2016-5424 · Exceptional database and role names could enable escalation to superuser CVSS 8.5
Fixed in this branch: 9.5.4. Component: client.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2016-5423 · Certain nested CASE/WHEN expressions can crash server CVSS 4.3
Fixed in this branch: 9.5.4. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2016-3065 · pageinspect does not check permissions for BRIN indexes CVSS 3.1
Fixed in this branch: 9.5.2. Component: contrib module.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2016-2193 · Plan cache might use wrong role context for RLS policy CVSS 4.2
Fixed in this branch: 9.5.2. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2016-0773 · Unchecked regex can crash the server CVSS 6.5
Fixed in this branch: 9.5.1. Component: core server.
Official affected-branch entry: 9.5.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2016-0766 · CVE-2016-0766
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases