PostgreSQL 9.6
Read the English manualEnd of life · Recorded build 9.6.24 · 2021-11-11
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2016-09-29
- Support end
- 2021-11-11
- Indexed releases
- 25
- Original release-note entries
- 1105
Manuals & provenance
PostgreSQL 9.6 English manual · 1046 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 9.6.0 · Changes from the initial release through 9.6.24
Original migration guidance for 9.6.0
A dump/restore using pg_dumpall, or use of pg_upgrade, is required for those wishing to migrate data from any previous release.
Version 9.6 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 9.6.24 | 2021-11-11 | 40 | 18 | 0 | 2 |
| 9.6.23 | 2021-08-12 | 47 | 16 | 0 | 2 |
| 9.6.22 | 2021-05-13 | 23 | 13 | 0 | 2 |
| 9.6.21 | 2021-02-11 | 36 | 18 | 0 | 0 |
| 9.6.20 | 2020-11-12 | 36 | 10 | 0 | 3 |
| 9.6.19 | 2020-08-13 | 27 | 13 | 0 | 2 |
| 9.6.18 | 2020-05-14 | 38 | 18 | 0 | 0 |
| 9.6.17 | 2020-02-13 | 33 | 17 | 0 | 1 |
| 9.6.16 | 2019-11-14 | 53 | 21 | 0 | 0 |
| 9.6.15 | 2019-08-08 | 26 | 10 | 0 | 2 |
| 9.6.14 | 2019-06-20 | 17 | 11 | 0 | 0 |
| 9.6.13 | 2019-05-09 | 33 | 18 | 0 | 2 |
| 9.6.12 | 2019-02-14 | 44 | 24 | 0 | 0 |
| 9.6.11 | 2018-11-08 | 57 | 27 | 0 | 0 |
| 9.6.10 | 2018-08-09 | 33 | 17 | 0 | 2 |
| 9.6.9 | 2018-05-10 | 43 | 24 | 0 | 1 |
| 9.6.8 | 2018-03-01 | 8 | 4 | 0 | 1 |
| 9.6.7 | 2018-02-08 | 37 | 20 | 0 | 1 |
| 9.6.6 | 2017-11-09 | 38 | 20 | 0 | 3 |
| 9.6.5 | 2017-08-31 | 10 | 3 | 0 | 0 |
| 9.6.4 | 2017-08-10 | 60 | 30 | 0 | 4 |
| 9.6.3 | 2017-05-11 | 48 | 30 | 0 | 4 |
| 9.6.2 | 2017-02-09 | 76 | 47 | 0 | 0 |
| 9.6.1 | 2016-10-27 | 28 | 17 | 0 | 0 |
| 9.6.0 | 2016-09-29 | 214 | 6 | 13 | 0 |
Initial release changes
Original entries from 9.6.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
214 of 214 original entries.
Improve the pg_stat_activity view's information about what a process is waiting for Compatibility Migration
Improve the pg_stat_activity view's information about what a process is waiting for (Amit Kapila, Ildus Kurbangaliev)
Historically a process has only been shown as waiting if it was waiting for a heavyweight lock. Now waits for lightweight locks and buffer pins are also shown in pg_stat_activity. Also, the type of lock being waited for is now visible. These changes replace the waiting column with wait_event_type and wait_event.
Original release occurrence ·
9.6.0/migration/001In to_char(), do not count a minus sign (when needed) as part of the field width for time-related fields Compatibility Migration
In
to_char(), do not count a minus sign (when needed) as part of the field width for time-related fields (Bruce Momjian)For example, to_char('-4 years'::interval, 'YY') now returns -04, rather than -4.
Original release occurrence ·
9.6.0/migration/002Make extract() behave more reasonably with infinite inputs Compatibility Migration
Make
extract()behave more reasonably with infinite inputs (Vitaly Burovoy)Historically the
extract()function just returned zero given an infinite timestamp, regardless of the given field name. Make it return infinity or -infinity as appropriate when the requested field is one that is monotonically increasing (e.g, year, epoch), or NULL when it is not (e.g., day, hour). Also, throw the expected error for bad field names.Original release occurrence ·
9.6.0/migration/003Remove PL/pgSQL's "feature" that suppressed the innermost line of CONTEXT for messages emitted by RAISE commands Compatibility Migration
Remove PL/pgSQL's "feature" that suppressed the innermost line of CONTEXT for messages emitted by RAISE commands (Pavel Stehule)
This ancient backwards-compatibility hack was agreed to have outlived its usefulness.
Original release occurrence ·
9.6.0/migration/004Fix the default text search parser to allow leading digits in email and host tokens Compatibility Migration
Fix the default text search parser to allow leading digits in email and host tokens (Artur Zakirov)
In most cases this will result in few changes in the parsing of text. But if you have data where such addresses occur frequently, it may be worth rebuilding dependent tsvector columns and indexes so that addresses of this form will be found properly by text searches.
Original release occurrence ·
9.6.0/migration/005Extend contrib/unaccent's standard unaccent.rules file to handle all diacritics known to Unicode, and to expand ligatures correctly Compatibility Migration
Extend contrib/unaccent's standard unaccent.rules file to handle all diacritics known to Unicode, and to expand ligatures correctly (Thomas Munro, Léonard Benedetti)
The previous version neglected to convert some less-common letters with diacritic marks. Also, ligatures are now expanded into separate letters. Installations that use this rules file may wish to rebuild tsvector columns and indexes that depend on the result.
Original release occurrence ·
9.6.0/migration/006Remove the long-deprecated CREATEUSER/NOCREATEUSER options from CREATE ROLE and allied commands Compatibility Migration
Remove the long-deprecated CREATEUSER/NOCREATEUSER options from CREATE ROLE and allied commands (Tom Lane)
CREATEUSER actually meant SUPERUSER, for ancient backwards-compatibility reasons. This has been a constant source of confusion for people who (reasonably) expect it to mean CREATEROLE. It has been deprecated for ten years now, so fix the problem by removing it.
Original release occurrence ·
9.6.0/migration/007Treat role names beginning with pg_ as reserved Compatibility Migration
Treat role names beginning with pg_ as reserved (Stephen Frost)
User creation of such role names is now disallowed. This prevents conflicts with built-in roles created by initdb.
Original release occurrence ·
9.6.0/migration/008Change a column name in the information_schema.routines view from result_cast_character_set_name to result_cast_char_set_name Compatibility Migration
Change a column name in the information_schema.routines view from result_cast_character_set_name to result_cast_char_set_name (Clément Prévost)
The SQL:2011 standard specifies the longer name, but that appears to be a mistake, because adjacent column names use the shorter style, as do other information_schema views.
Original release occurrence ·
9.6.0/migration/009psql's -c option no longer implies --no-psqlrc Compatibility Migration
psql's -c option no longer implies --no-psqlrc (Pavel Stehule, Catalin Iacob)
Write --no-psqlrc (or its abbreviation -X) explicitly to obtain the old behavior. Scripts so modified will still work with old versions of psql.
Original release occurrence ·
9.6.0/migration/010Improve pg_restore's -t option to match all types of relations, not only plain tables Compatibility Migration
Improve pg_restore's -t option to match all types of relations, not only plain tables (Craig Ringer)
Original release occurrence ·
9.6.0/migration/011Change the display format used for NextXID in pg_controldata and related places Compatibility Migration
Change the display format used for NextXID in pg_controldata and related places (Joe Conway, Bruce Momjian)
Display epoch-and-transaction-ID values in the format number:number. The previous format number/number was confusingly similar to that used for LSNs.
Original release occurrence ·
9.6.0/migration/012Update extension functions to be marked parallel-safe where appropriate Compatibility Migration
Update extension functions to be marked parallel-safe where appropriate (Andreas Karlsson)
Many of the standard extensions have been updated to allow their functions to be executed within parallel query worker processes. These changes will not take effect in databases pg_upgrade'd from prior versions unless you apply ALTER EXTENSION UPDATE to each such extension (in each database of a cluster).
Original release occurrence ·
9.6.0/migration/013Parallel queries Features
Parallel queries (Robert Haas, Amit Kapila, David Rowley, many others)
With 9.6, PostgreSQL introduces initial support for parallel execution of large queries. Only strictly read-only queries where the driving table is accessed via a sequential scan can be parallelized. Hash joins and nested loops can be performed in parallel, as can aggregation (for supported aggregates). Much remains to be done, but this is already a useful set of features.
Parallel query execution is not (yet) enabled by default. To allow it, set the new configuration parameter max_parallel_workers_per_gather to a value larger than zero. Additional control over use of parallelism is available through other new configuration parameters force_parallel_mode, parallel_setup_cost, parallel_tuple_cost, and min_parallel_relation_size.
Original release occurrence ·
9.6.0/changes/001Provide infrastructure for marking the parallel-safety status of functions Features
Provide infrastructure for marking the parallel-safety status of functions (Robert Haas, Amit Kapila)
Original release occurrence ·
9.6.0/changes/002Allow GIN index builds to make effective use of maintenance_work_mem settings larger than 1 GB Features
Allow GIN index builds to make effective use of maintenance_work_mem settings larger than 1 GB (Robert Abraham, Teodor Sigaev)
Original release occurrence ·
9.6.0/changes/003Add pages deleted from a GIN index's pending list to the free space map immediately Features
Add pages deleted from a GIN index's pending list to the free space map immediately (Jeff Janes, Teodor Sigaev)
This reduces bloat if the table is not vacuumed often.
Original release occurrence ·
9.6.0/changes/004Add gin_clean_pending_list() function to allow manual invocation of pending-list cleanup for a GIN index Features
Add
gin_clean_pending_list()function to allow manual invocation of pending-list cleanup for a GIN index (Jeff Janes)Formerly, such cleanup happened only as a byproduct of vacuuming or analyzing the parent table.
Original release occurrence ·
9.6.0/changes/005Improve handling of dead index tuples in GiST indexes Features
Improve handling of dead index tuples in GiST indexes (Anastasia Lubennikova)
Dead index tuples are now marked as such when an index scan notices that the corresponding heap tuple is dead. When inserting tuples, marked-dead tuples will be removed if needed to make space on the page.
Original release occurrence ·
9.6.0/changes/006Add an SP-GiST operator class for type box Features
Add an SP-GiST operator class for type box (Alexander Lebedev)
Original release occurrence ·
9.6.0/changes/007Improve sorting performance by using quicksort, not replacement selection sort, when performing external sort steps Performance
Improve sorting performance by using quicksort, not replacement selection sort, when performing external sort steps (Peter Geoghegan)
The new approach makes better use of the CPU cache for typical cache sizes and data volumes. Where necessary, the behavior can be adjusted via the new configuration parameter replacement_sort_tuples.
Original release occurrence ·
9.6.0/changes/008Speed up text sorts where the same string occurs multiple times Performance
Speed up text sorts where the same string occurs multiple times (Peter Geoghegan)
Original release occurrence ·
9.6.0/changes/009Speed up sorting of uuid, bytea, and char(n) fields by using "abbreviated" keys Performance
Speed up sorting of uuid, bytea, and char(n) fields by using "abbreviated" keys (Peter Geoghegan)
Support for abbreviated keys has also been added to the non-default operator classes text_pattern_ops, varchar_pattern_ops, and bpchar_pattern_ops. Processing of ordered-set aggregates can also now exploit abbreviated keys.
Original release occurrence ·
9.6.0/changes/010Speed up CREATE INDEX CONCURRENTLY by treating TIDs as 64-bit integers during sorting Performance
Speed up CREATE INDEX CONCURRENTLY by treating TIDs as 64-bit integers during sorting (Peter Geoghegan)
Original release occurrence ·
9.6.0/changes/011Reduce contention for the ProcArrayLock Features
Reduce contention for the ProcArrayLock (Amit Kapila, Robert Haas)
Original release occurrence ·
9.6.0/changes/012Improve performance by moving buffer content locks into the buffer descriptors Performance
Improve performance by moving buffer content locks into the buffer descriptors (Andres Freund, Simon Riggs)
Original release occurrence ·
9.6.0/changes/013Replace shared-buffer header spinlocks with atomic operations to improve scalability Features
Replace shared-buffer header spinlocks with atomic operations to improve scalability (Alexander Korotkov, Andres Freund)
Original release occurrence ·
9.6.0/changes/014Use atomic operations, rather than a spinlock, to protect an LWLock's wait queue Features
Use atomic operations, rather than a spinlock, to protect an LWLock's wait queue (Andres Freund)
Original release occurrence ·
9.6.0/changes/015Partition the shared hash table freelist to reduce contention on multi-CPU-socket servers Features
Partition the shared hash table freelist to reduce contention on multi-CPU-socket servers (Aleksander Alekseev)
Original release occurrence ·
9.6.0/changes/016Reduce interlocking on standby servers during the replay of btree index vacuuming operations Features
Reduce interlocking on standby servers during the replay of btree index vacuuming operations (Simon Riggs)
This change avoids substantial replication delays that sometimes occurred while replaying such operations.
Original release occurrence ·
9.6.0/changes/017Improve ANALYZE's estimates for columns with many nulls Features
Improve ANALYZE's estimates for columns with many nulls (Tomas Vondra, Alex Shulgin)
Previously ANALYZE tended to underestimate the number of non-NULL distinct values in a column with many NULLs, and was also inaccurate in computing the most-common values.
Original release occurrence ·
9.6.0/changes/018Improve planner's estimate of the number of distinct values in a query result Features
Improve planner's estimate of the number of distinct values in a query result (Tomas Vondra)
Original release occurrence ·
9.6.0/changes/019Use foreign key relationships to infer selectivity for join predicates Features
Use foreign key relationships to infer selectivity for join predicates (Tomas Vondra, David Rowley)
If a table t has a foreign key restriction, say (a,b) REFERENCES r (x,y), then a WHERE condition such as t.a = r.x AND t.b = r.y cannot select more than one r row per t row. The planner formerly considered these AND conditions to be independent and would often drastically misestimate selectivity as a result. Now it compares the WHERE conditions to applicable foreign key constraints and produces better estimates.
Original release occurrence ·
9.6.0/changes/020Avoid re-vacuuming pages containing only frozen tuples Features
Avoid re-vacuuming pages containing only frozen tuples (Masahiko Sawada, Robert Haas, Andres Freund)
Formerly, anti-wraparound vacuum had to visit every page of a table, even pages where there was nothing to do. Now, pages containing only already-frozen tuples are identified in the table's visibility map, and can be skipped by vacuum even when doing transaction wraparound prevention. This should greatly reduce the cost of maintaining large tables containing mostly-unchanging data.
If necessary, vacuum can be forced to process all-frozen pages using the new DISABLE_PAGE_SKIPPING option. Normally this should never be needed, but it might help in recovering from visibility-map corruption.
Original release occurrence ·
9.6.0/changes/021Avoid useless heap-truncation attempts during VACUUM Features
Avoid useless heap-truncation attempts during VACUUM (Jeff Janes, Tom Lane)
This change avoids taking an exclusive table lock in some cases where no truncation is possible. The main benefit comes from avoiding unnecessary query cancellations on standby servers.
Original release occurrence ·
9.6.0/changes/022Allow old MVCC snapshots to be invalidated after a configurable timeout Performance
Allow old MVCC snapshots to be invalidated after a configurable timeout (Kevin Grittner)
Normally, deleted tuples cannot be physically removed by vacuuming until the last transaction that could "see" them is gone. A transaction that stays open for a long time can thus cause considerable table bloat because space cannot be recycled. This feature allows setting a time-based limit, via the new configuration parameter old_snapshot_threshold, on how long an MVCC snapshot is guaranteed to be valid. After that, dead tuples are candidates for removal. A transaction using an outdated snapshot will get an error if it attempts to read a page that potentially could have contained such data.
Original release occurrence ·
9.6.0/changes/023Ignore GROUP BY columns that are functionally dependent on other columns Performance
Ignore GROUP BY columns that are functionally dependent on other columns (David Rowley)
If a GROUP BY clause includes all columns of a non-deferred primary key, as well as other columns of the same table, those other columns are redundant and can be dropped from the grouping. This saves computation in many common cases.
Original release occurrence ·
9.6.0/changes/024Allow use of an index-only scan on a partial index when the index's WHERE clause references columns that are not indexed Performance
Allow use of an index-only scan on a partial index when the index's WHERE clause references columns that are not indexed (Tomas Vondra, Kyotaro Horiguchi)
For example, an index defined by CREATE INDEX tidx_partial ON t(b) WHERE a > 0 can now be used for an index-only scan by a query that specifies WHERE a > 0 and does not otherwise use a. Previously this was disallowed because a is not listed as an index column.
Original release occurrence ·
9.6.0/changes/025Perform checkpoint writes in sorted order Performance
Perform checkpoint writes in sorted order (Fabien Coelho, Andres Freund)
Previously, checkpoints wrote out dirty pages in whatever order they happen to appear in shared buffers, which usually is nearly random. That performs poorly, especially on rotating media. This change causes checkpoint-driven writes to be done in order by file and block number, and to be balanced across tablespaces.
Original release occurrence ·
9.6.0/changes/026Where feasible, trigger kernel writeback after a configurable number of writes, to prevent accumulation of dirty data in kernel disk buffers Performance
Where feasible, trigger kernel writeback after a configurable number of writes, to prevent accumulation of dirty data in kernel disk buffers (Fabien Coelho, Andres Freund)
PostgreSQL writes data to the kernel's disk cache, from where it will be flushed to physical storage in due time. Many operating systems are not smart about managing this and allow large amounts of dirty data to accumulate before deciding to flush it all at once, causing long delays for new I/O requests until the flushing finishes. This change attempts to alleviate this problem by explicitly requesting data flushes after a configurable interval.
On Linux,
sync_file_range()is used for this purpose, and the feature is on by default on Linux because that function has few downsides. This flushing capability is also available on other platforms if they havemsync()orposix_fadvise(), but those interfaces have some undesirable side-effects so the feature is disabled by default on non-Linux platforms.The new configuration parameters backend_flush_after, bgwriter_flush_after, checkpoint_flush_after, and wal_writer_flush_after control this behavior.
Original release occurrence ·
9.6.0/changes/027Improve aggregate-function performance by sharing calculations across multiple aggregates if they have the same arguments and transition functions Performance
Improve aggregate-function performance by sharing calculations across multiple aggregates if they have the same arguments and transition functions (David Rowley)
For example, SELECT AVG(x), VARIANCE(x) FROM tab can use a single per-row computation for both aggregates.
Original release occurrence ·
9.6.0/changes/028Speed up visibility tests for recently-created tuples by checking the current transaction's snapshot, not pg_clog, to decide if the source transaction should be considered committed Performance
Speed up visibility tests for recently-created tuples by checking the current transaction's snapshot, not pg_clog, to decide if the source transaction should be considered committed (Jeff Janes, Tom Lane)
Original release occurrence ·
9.6.0/changes/029Allow tuple hint bits to be set sooner than before Performance
Allow tuple hint bits to be set sooner than before (Andres Freund)
Original release occurrence ·
9.6.0/changes/030Improve performance of short-lived prepared transactions Performance
Improve performance of short-lived prepared transactions (Stas Kelvich, Simon Riggs, Pavan Deolasee)
Two-phase commit information is now written only to WAL during PREPARE TRANSACTION, and will be read back from WAL during COMMIT PREPARED if that happens soon thereafter. A separate state file is created only if the pending transaction does not get committed or aborted by the time of the next checkpoint.
Original release occurrence ·
9.6.0/changes/031Improve performance of memory context destruction Performance
Improve performance of memory context destruction (Jan Wieck)
Original release occurrence ·
9.6.0/changes/032Improve performance of resource owners with many tracked objects Performance
Improve performance of resource owners with many tracked objects (Aleksander Alekseev)
Original release occurrence ·
9.6.0/changes/033Improve speed of the output functions for timestamp, time, and date data types Performance
Improve speed of the output functions for timestamp, time, and date data types (David Rowley, Andres Freund)
Original release occurrence ·
9.6.0/changes/034Avoid some unnecessary cancellations of hot-standby queries during replay of actions that take AccessExclusive locks Performance
Avoid some unnecessary cancellations of hot-standby queries during replay of actions that take AccessExclusive locks (Jeff Janes)
Original release occurrence ·
9.6.0/changes/035Extend relations multiple blocks at a time when there is contention for the relation's extension lock Performance
Extend relations multiple blocks at a time when there is contention for the relation's extension lock (Dilip Kumar)
This improves scalability by decreasing contention.
Original release occurrence ·
9.6.0/changes/036Increase the number of clog buffers for better scalability Performance
Increase the number of clog buffers for better scalability (Amit Kapila, Andres Freund)
Original release occurrence ·
9.6.0/changes/037Speed up expression evaluation in PL/pgSQL by keeping ParamListInfo entries for simple variables valid at all times Performance
Speed up expression evaluation in PL/pgSQL by keeping ParamListInfo entries for simple variables valid at all times (Tom Lane)
Original release occurrence ·
9.6.0/changes/038Avoid reducing the SO_SNDBUF setting below its default on recent Windows versions Performance
Avoid reducing the SO_SNDBUF setting below its default on recent Windows versions (Chen Huajun)
Original release occurrence ·
9.6.0/changes/039Disable update_process_title by default on Windows Performance
Disable update_process_title by default on Windows (Takayuki Tsunakawa)
The overhead of updating the process title is much larger on Windows than most other platforms, and it is also less useful to do it since most Windows users do not have tools that can display process titles.
Original release occurrence ·
9.6.0/changes/040Add pg_stat_progress_vacuum system view to provide progress reporting for VACUUM operations Features
Add pg_stat_progress_vacuum system view to provide progress reporting for VACUUM operations (Amit Langote, Robert Haas, Vinayak Pokale, Rahila Syed)
Original release occurrence ·
9.6.0/changes/041Add pg_control_system(), pg_control_checkpoint(), pg_control_recovery(), and pg_control_init() functions to expose fields of pg_control to SQL Features
Add
pg_control_system(),pg_control_checkpoint(),pg_control_recovery(), andpg_control_init()functions to expose fields of pg_control to SQL (Joe Conway, Michael Paquier)Original release occurrence ·
9.6.0/changes/042Add pg_config system view Features
Add pg_config system view (Joe Conway)
This view exposes the same information available from the pg_config command-line utility, namely assorted compile-time configuration information for PostgreSQL.
Original release occurrence ·
9.6.0/changes/043Add a confirmed_flush_lsn column to the pg_replication_slots system view Features
Add a confirmed_flush_lsn column to the pg_replication_slots system view (Marko Tiikkaja)
Original release occurrence ·
9.6.0/changes/044Add pg_stat_wal_receiver system view to provide information about the state of a hot-standby server's WAL receiver process Features
Add pg_stat_wal_receiver system view to provide information about the state of a hot-standby server's WAL receiver process (Michael Paquier)
Original release occurrence ·
9.6.0/changes/045Add pg_blocking_pids() function to reliably identify which sessions block which others Features
Add
pg_blocking_pids()function to reliably identify which sessions block which others (Tom Lane)This function returns an array of the process IDs of any sessions that are blocking the session with the given process ID. Historically users have obtained such information using a self-join on the pg_locks view. However, it is unreasonably tedious to do it that way with any modicum of correctness, and the addition of parallel queries has made the old approach entirely impractical, since locks might be held or awaited by child worker processes rather than the session's main process.
Original release occurrence ·
9.6.0/changes/046Add function pg_current_xlog_flush_location() to expose the current transaction log flush location Features
Add function
pg_current_xlog_flush_location()to expose the current transaction log flush location (Tomas Vondra)Original release occurrence ·
9.6.0/changes/047Add function pg_notification_queue_usage() to report how full the NOTIFY queue is Features
Add function
pg_notification_queue_usage()to report how full the NOTIFY queue is (Brendan Jurd)Original release occurrence ·
9.6.0/changes/048Limit the verbosity of memory context statistics dumps Features
Limit the verbosity of memory context statistics dumps (Tom Lane)
The memory usage dump that is output to the postmaster log during an out-of-memory failure now summarizes statistics when there are a large number of memory contexts, rather than possibly generating a very large report. There is also a "grand total" summary line now.
Original release occurrence ·
9.6.0/changes/049Add a BSD authentication method to allow use of the BSD Authentication service for PostgreSQL client authentication Features
Add a BSD authentication method to allow use of the BSD Authentication service for PostgreSQL client authentication (Marisa Emerson)
BSD Authentication is currently only available on OpenBSD.
Original release occurrence ·
9.6.0/changes/050When using PAM authentication, provide the client IP address or host name to PAM modules via the PAM_RHOST item Features
When using PAM authentication, provide the client IP address or host name to PAM modules via the PAM_RHOST item (Grzegorz Sampolski)
Original release occurrence ·
9.6.0/changes/051Provide detail in the postmaster log for more types of password authentication failure Features
Provide detail in the postmaster log for more types of password authentication failure (Tom Lane)
All ordinarily-reachable password authentication failure cases should now provide specific DETAIL fields in the log.
Original release occurrence ·
9.6.0/changes/052Support RADIUS passwords up to 128 characters long Features
Support RADIUS passwords up to 128 characters long (Marko Tiikkaja)
Original release occurrence ·
9.6.0/changes/053Add new SSPI authentication parameters compat_realm and upn_username to control whether NetBIOS or Kerberos realm names and user names are used during SSPI authentication Features
Add new SSPI authentication parameters compat_realm and upn_username to control whether NetBIOS or Kerberos realm names and user names are used during SSPI authentication (Christian Ullrich)
Original release occurrence ·
9.6.0/changes/054Allow sessions to be terminated automatically if they are in idle-in-transaction state for too long Features
Allow sessions to be terminated automatically if they are in idle-in-transaction state for too long (Vik Fearing)
This behavior is controlled by the new configuration parameter idle_in_transaction_session_timeout. It can be useful to prevent forgotten transactions from holding locks or preventing vacuum cleanup for too long.
Original release occurrence ·
9.6.0/changes/055Raise the maximum allowed value of checkpoint_timeout to 24 hours Features
Raise the maximum allowed value of checkpoint_timeout to 24 hours (Simon Riggs)
Original release occurrence ·
9.6.0/changes/056Allow effective_io_concurrency to be set per-tablespace to support cases where different tablespaces have different I/O characteristics Features
Allow effective_io_concurrency to be set per-tablespace to support cases where different tablespaces have different I/O characteristics (Julien Rouhaud)
Original release occurrence ·
9.6.0/changes/057Add log_line_prefix option %n to print the current time in Unix epoch form, with milliseconds Features
Add log_line_prefix option %n to print the current time in Unix epoch form, with milliseconds (Tomas Vondra, Jeff Davis)
Original release occurrence ·
9.6.0/changes/058Add syslog_sequence_numbers and syslog_split_messages configuration parameters to provide more control over the message format when logging to syslog Features
Add syslog_sequence_numbers and syslog_split_messages configuration parameters to provide more control over the message format when logging to syslog (Peter Eisentraut)
Original release occurrence ·
9.6.0/changes/059Merge the archive and hot_standby values of the wal_level configuration parameter into a single new value replica Features
Merge the archive and hot_standby values of the wal_level configuration parameter into a single new value replica (Peter Eisentraut)
Making a distinction between these settings is no longer useful, and merging them is a step towards a planned future simplification of replication setup. The old names are still accepted but are converted to replica internally.
Original release occurrence ·
9.6.0/changes/060Add configure option --with-systemd to enable calling sd_notify() at server start and stop Features
Add configure option --with-systemd to enable calling
sd_notify()at server start and stop (Peter Eisentraut)This allows the use of systemd service units of type notify, which greatly simplifies the management of PostgreSQL under systemd.
Original release occurrence ·
9.6.0/changes/061Allow the server's SSL key file to have group read access if it is owned by root Features
Allow the server's SSL key file to have group read access if it is owned by root (Christoph Berg)
Formerly, we insisted the key file be owned by the user running the PostgreSQL server, but that is inconvenient on some systems (such as Debian) that are configured to manage certificates centrally. Therefore, allow the case where the key file is owned by root and has group read access. It is up to the operating system administrator to ensure that the group does not include any untrusted users.
Original release occurrence ·
9.6.0/changes/062Force backends to exit if the postmaster dies Features
Force backends to exit if the postmaster dies (Rajeev Rastogi, Robert Haas)
Under normal circumstances the postmaster should always outlive its child processes. If for some reason the postmaster dies, force backend sessions to exit with an error. Formerly, existing backends would continue to run until their clients disconnect, but that is unsafe and inefficient. It also prevents a new postmaster from being started until the last old backend has exited. Backends will detect postmaster death when waiting for client I/O, so the exit will not be instantaneous, but it should happen no later than the end of the current query.
Original release occurrence ·
9.6.0/changes/063Check for serializability conflicts before reporting constraint-violation failures Features
Check for serializability conflicts before reporting constraint-violation failures (Thomas Munro)
When using serializable transaction isolation, it is desirable that any error due to concurrent transactions should manifest as a serialization failure, thereby cueing the application that a retry might succeed. Unfortunately, this does not reliably happen for duplicate-key failures caused by concurrent insertions. This change ensures that such an error will be reported as a serialization error if the application explicitly checked for the presence of a conflicting key (and did not find it) earlier in the transaction.
Original release occurrence ·
9.6.0/changes/064Ensure that invalidation messages are recorded in WAL even when issued by a transaction that has no XID assigned Features
Ensure that invalidation messages are recorded in WAL even when issued by a transaction that has no XID assigned (Andres Freund)
This fixes some corner cases in which transactions on standby servers failed to notice changes, such as new indexes.
Original release occurrence ·
9.6.0/changes/065Prevent multiple processes from trying to clean a GIN index's pending list concurrently Features
Prevent multiple processes from trying to clean a GIN index's pending list concurrently (Teodor Sigaev, Jeff Janes)
This had been intentionally allowed, but it causes race conditions that can result in vacuum missing index entries it needs to delete.
Original release occurrence ·
9.6.0/changes/066Allow synchronous replication to support multiple simultaneous synchronous standby servers, not just one Features
Allow synchronous replication to support multiple simultaneous synchronous standby servers, not just one (Masahiko Sawada, Beena Emerson, Michael Paquier, Fujii Masao, Kyotaro Horiguchi)
The number of standby servers that must acknowledge a commit before it is considered complete is now configurable as part of the synchronous_standby_names parameter.
Original release occurrence ·
9.6.0/changes/067Add new setting remote_apply for configuration parameter synchronous_commit Features
Add new setting remote_apply for configuration parameter synchronous_commit (Thomas Munro)
In this mode, the master waits for the transaction to be applied on the standby server, not just written to disk. That means that you can count on a transaction started on the standby to see all commits previously acknowledged by the master.
Original release occurrence ·
9.6.0/changes/068Add a feature to the replication protocol, and a corresponding option to pg_create_physical_replication_slot(), to allow reserving WAL immediately when creating a replication slot Features
Add a feature to the replication protocol, and a corresponding option to
pg_create_physical_replication_slot(), to allow reserving WAL immediately when creating a replication slot (Gurjeet Singh, Michael Paquier)This allows the creation of a replication slot to guarantee that all the WAL needed for a base backup will be available.
Original release occurrence ·
9.6.0/changes/069Add a --slot option to pg_basebackup Features
Add a --slot option to pg_basebackup (Peter Eisentraut)
This lets pg_basebackup use a replication slot defined for WAL streaming. After the base backup completes, selecting the same slot for regular streaming replication allows seamless startup of the new standby server.
Original release occurrence ·
9.6.0/changes/070Extend pg_start_backup() and pg_stop_backup() to support non-exclusive backups Features
Extend
pg_start_backup()andpg_stop_backup()to support non-exclusive backups (Magnus Hagander)Original release occurrence ·
9.6.0/changes/071Allow functions that return sets of tuples to return simple NULLs Features
Allow functions that return sets of tuples to return simple NULLs (Andrew Gierth, Tom Lane)
In the context of SELECT FROM function(...), a function that returned a set of composite values was previously not allowed to return a plain NULL value as part of the set. Now that is allowed and interpreted as a row of NULLs. This avoids corner-case errors with, for example, unnesting an array of composite values.
Original release occurrence ·
9.6.0/changes/072Fully support array subscripts and field selections in the target column list of an INSERT with multiple VALUES rows Features
Fully support array subscripts and field selections in the target column list of an INSERT with multiple VALUES rows (Tom Lane)
Previously, such cases failed if the same target column was mentioned more than once, e.g., INSERT INTO tab (x[1], x[2]) VALUES (...).
Original release occurrence ·
9.6.0/changes/073When appropriate, postpone evaluation of SELECT output expressions until after an ORDER BY sort Features
When appropriate, postpone evaluation of SELECT output expressions until after an ORDER BY sort (Konstantin Knizhnik)
This change ensures that volatile or expensive functions in the output list are executed in the order suggested by ORDER BY, and that they are not evaluated more times than required when there is a LIMIT clause. Previously, these properties held if the ordering was performed by an index scan or pre-merge-join sort, but not if it was performed by a top-level sort.
Original release occurrence ·
9.6.0/changes/074Widen counters recording the number of tuples processed to 64 bits Features
Widen counters recording the number of tuples processed to 64 bits (Andreas Scherbaum)
This change allows command tags, e.g., SELECT, to correctly report tuple counts larger than 4 billion. This also applies to PL/pgSQL's GET DIAGNOSTICS ... ROW_COUNT command.
Original release occurrence ·
9.6.0/changes/075Avoid doing encoding conversions by converting through the MULE_INTERNAL encoding Features
Avoid doing encoding conversions by converting through the MULE_INTERNAL encoding (Tom Lane)
Previously, many conversions for Cyrillic and Central European single-byte encodings were done by converting to a related MULE_INTERNAL coding scheme and then to the destination encoding. Aside from being inefficient, this meant that when the conversion encountered an untranslatable character, the error message would confusingly complain about failure to convert to or from MULE_INTERNAL, rather than the user-visible encoding.
Original release occurrence ·
9.6.0/changes/076Consider performing joins of foreign tables remotely only when the tables will be accessed under the same role ID Features
Consider performing joins of foreign tables remotely only when the tables will be accessed under the same role ID (Shigeru Hanada, Ashutosh Bapat, Etsuro Fujita)
Previously, the foreign join pushdown infrastructure left the question of security entirely up to individual foreign data wrappers, but that made it too easy for an FDW to inadvertently create subtle security holes. So, make it the core code's job to determine which role ID will access each table, and do not attempt join pushdown unless the role is the same for all relevant relations.
Original release occurrence ·
9.6.0/changes/077Allow COPY to copy the output of an INSERT/UPDATE/DELETE ... RETURNING query Features
Allow COPY to copy the output of an INSERT/UPDATE/DELETE ... RETURNING query (Marko Tiikkaja)
Previously, an intermediate CTE had to be written to get this result.
Original release occurrence ·
9.6.0/changes/078Introduce ALTER object DEPENDS ON EXTENSION Features
Introduce ALTER object DEPENDS ON EXTENSION (Abhijit Menon-Sen)
This command allows a database object to be marked as depending on an extension, so that it will be dropped automatically if the extension is dropped (without needing CASCADE). However, the object is not part of the extension, and thus will be dumped separately by pg_dump.
Original release occurrence ·
9.6.0/changes/079Make ALTER object SET SCHEMA do nothing when the object is already in the requested schema, rather than throwing an error as it historically has for most object types Features
Make ALTER object SET SCHEMA do nothing when the object is already in the requested schema, rather than throwing an error as it historically has for most object types (Marti Raudsepp)
Original release occurrence ·
9.6.0/changes/080Add options to ALTER OPERATOR to allow changing the selectivity functions associated with an existing operator Features
Add options to ALTER OPERATOR to allow changing the selectivity functions associated with an existing operator (Yury Zhuravlev)
Original release occurrence ·
9.6.0/changes/081Add an IF NOT EXISTS option to ALTER TABLE ADD COLUMN Features
Add an IF NOT EXISTS option to ALTER TABLE ADD COLUMN (Fabrízio de Royes Mello)
Original release occurrence ·
9.6.0/changes/082Reduce the lock strength needed by ALTER TABLE when setting fillfactor and autovacuum-related relation options Features
Reduce the lock strength needed by ALTER TABLE when setting fillfactor and autovacuum-related relation options (Fabrízio de Royes Mello, Simon Riggs)
Original release occurrence ·
9.6.0/changes/083Introduce CREATE ACCESS METHOD to allow extensions to create index access methods Features
Introduce CREATE ACCESS METHOD to allow extensions to create index access methods (Alexander Korotkov, Petr Jelínek)
Original release occurrence ·
9.6.0/changes/084Add a CASCADE option to CREATE EXTENSION to automatically create any extensions the requested one depends on Features
Add a CASCADE option to CREATE EXTENSION to automatically create any extensions the requested one depends on (Petr Jelínek)
Original release occurrence ·
9.6.0/changes/085Make CREATE TABLE ... LIKE include an OID column if any source table has one Features
Make CREATE TABLE ... LIKE include an OID column if any source table has one (Bruce Momjian)
Original release occurrence ·
9.6.0/changes/086If a CHECK constraint is declared NOT VALID in a table creation command, automatically mark it as valid Features
If a CHECK constraint is declared NOT VALID in a table creation command, automatically mark it as valid (Amit Langote, Amul Sul)
This is safe because the table has no existing rows. This matches the longstanding behavior of FOREIGN KEY constraints.
Original release occurrence ·
9.6.0/changes/087Fix DROP OPERATOR to clear pg_operator.oprcom and pg_operator.oprnegate links to the dropped operator Bug fixes
Fix DROP OPERATOR to clear pg_operator.oprcom and pg_operator.oprnegate links to the dropped operator (Roma Sokolov)
Formerly such links were left as-is, which could pose a problem in the somewhat unlikely event that the dropped operator's OID was reused for another operator.
Original release occurrence ·
9.6.0/changes/088Do not show the same subplan twice in EXPLAIN output Features
Do not show the same subplan twice in EXPLAIN output (Tom Lane)
In certain cases, typically involving SubPlan nodes in index conditions, EXPLAIN would print data for the same subplan twice.
Original release occurrence ·
9.6.0/changes/089Disallow creation of indexes on system columns, except for OID columns Features
Disallow creation of indexes on system columns, except for OID columns (David Rowley)
Such indexes were never considered supported, and would very possibly misbehave since the system might change the system-column fields of a tuple without updating indexes. However, previously there were no error checks to prevent them from being created.
Original release occurrence ·
9.6.0/changes/090Use the privilege system to manage access to sensitive functions Features
Use the privilege system to manage access to sensitive functions (Stephen Frost)
Formerly, many security-sensitive functions contained hard-wired checks that would throw an error if they were called by a non-superuser. This forced the use of superuser roles for some relatively pedestrian tasks. The hard-wired error checks are now gone in favor of making initdb revoke the default public EXECUTE privilege on these functions. This allows installations to choose to grant usage of such functions to trusted roles that do not need all superuser privileges.
Original release occurrence ·
9.6.0/changes/091Create some built-in roles that can be used to grant access to what were previously superuser-only functions Features
Create some built-in roles that can be used to grant access to what were previously superuser-only functions (Stephen Frost)
Currently the only such role is pg_signal_backend, but more are expected to be added in future.
Original release occurrence ·
9.6.0/changes/092Improve full-text search to support searching for phrases, that is, lexemes appearing adjacent to each other in a specific order, or with a specified distance between them Features
Improve full-text search to support searching for phrases, that is, lexemes appearing adjacent to each other in a specific order, or with a specified distance between them (Teodor Sigaev, Oleg Bartunov, Dmitry Ivanov)
A phrase-search query can be specified in tsquery input using the new operators <-> and <N>. The former means that the lexemes before and after it must appear adjacent to each other in that order. The latter means they must be exactly N lexemes apart.
Original release occurrence ·
9.6.0/changes/093Allow omitting one or both boundaries in an array slice specifier, e.g., array_col[3:] Features
Allow omitting one or both boundaries in an array slice specifier, e.g., array_col[3:] (Yury Zhuravlev)
Omitted boundaries are taken as the upper or lower limit of the corresponding array subscript. This allows simpler specification for many common use-cases.
Original release occurrence ·
9.6.0/changes/094Be more careful about out-of-range dates and timestamps Features
Be more careful about out-of-range dates and timestamps (Vitaly Burovoy)
This change prevents unexpected out-of-range errors for timestamp with time zone values very close to the implementation limits. Previously, the "same" value might be accepted or not depending on the timezone setting, meaning that a dump and reload could fail on a value that had been accepted when presented. Now the limits are enforced according to the equivalent UTC time, not local time, so as to be independent of timezone.
Also, PostgreSQL is now more careful to detect overflow in operations that compute new date or timestamp values, such as date + integer.
Original release occurrence ·
9.6.0/changes/095For geometric data types, make sure infinity and NaN component values are treated consistently during input and output Features
For geometric data types, make sure infinity and NaN component values are treated consistently during input and output (Tom Lane)
Such values will now always print the same as they would in a simple float8 column, and be accepted the same way on input. Previously the behavior was platform-dependent.
Original release occurrence ·
9.6.0/changes/096Upgrade the ispell dictionary type to handle modern Hunspell files and support more languages Features
Upgrade the ispell dictionary type to handle modern Hunspell files and support more languages (Artur Zakirov)
Original release occurrence ·
9.6.0/changes/097Implement look-behind constraints in regular expressions Features
Implement look-behind constraints in regular expressions (Tom Lane)
A look-behind constraint is like a lookahead constraint in that it consumes no text; but it checks for existence (or nonexistence) of a match ending at the current point in the string, rather than one starting at the current point. Similar features exist in many other regular-expression engines.
Original release occurrence ·
9.6.0/changes/098In regular expressions, if an apparent three-digit octal escape \nnn would exceed 377 (255 decimal), assume it is a two-digit octal escape instead Features
In regular expressions, if an apparent three-digit octal escape \nnn would exceed 377 (255 decimal), assume it is a two-digit octal escape instead (Tom Lane)
This makes the behavior match current Tcl releases.
Original release occurrence ·
9.6.0/changes/099Add transaction ID operators xid <> xid and xid <> int4, for consistency with the corresponding equality operators Features
Add transaction ID operators xid <> xid and xid <> int4, for consistency with the corresponding equality operators (Michael Paquier)
Original release occurrence ·
9.6.0/changes/100Add jsonb_insert() function to insert a new element into a jsonb array, or a not-previously-existing key into a jsonb object Features
Add
jsonb_insert()function to insert a new element into a jsonb array, or a not-previously-existing key into a jsonb object (Dmitry Dolgov)Original release occurrence ·
9.6.0/changes/101Improve the accuracy of the ln(), log(), exp(), and pow() functions for type numeric Features
Improve the accuracy of the
ln(),log(),exp(), andpow()functions for type numeric (Dean Rasheed)Original release occurrence ·
9.6.0/changes/102Add a scale(numeric) function to extract the display scale of a numeric value Features
Add a
scale(numeric)function to extract the display scale of a numeric value (Marko Tiikkaja)Original release occurrence ·
9.6.0/changes/103Add trigonometric functions that work in degrees Features
Add trigonometric functions that work in degrees (Dean Rasheed)
For example,
sind()measures its argument in degrees, whereassin()measures in radians. These functions go to some lengths to deliver exact results for values where an exact result can be expected, for instance sind(30) = 0.5.Original release occurrence ·
9.6.0/changes/104Ensure that trigonometric functions handle infinity and NaN inputs per the POSIX standard Features
Ensure that trigonometric functions handle infinity and NaN inputs per the POSIX standard (Dean Rasheed)
The POSIX standard says that these functions should return NaN for NaN input, and should throw an error for out-of-range inputs including infinity. Previously our behavior varied across platforms.
Original release occurrence ·
9.6.0/changes/105Make to_timestamp(float8) convert float infinity to timestamp infinity Features
Make
to_timestamp(float8)convert float infinity to timestamp infinity (Vitaly Burovoy)Formerly it just failed on an infinite input.
Original release occurrence ·
9.6.0/changes/106Add new functions for tsvector data Features
Add new functions for tsvector data (Stas Kelvich)
The new functions are
ts_delete(),ts_filter(),unnest(),tsvector_to_array(),array_to_tsvector(), and a variant ofsetweight()that sets the weight only for specified lexeme(s).Original release occurrence ·
9.6.0/changes/107Allow ts_stat() and tsvector_update_trigger() to operate on values that are of types binary-compatible with the expected argument type, not just exactly that type; for example allow citext where text is expected Features
Allow
ts_stat()andtsvector_update_trigger()to operate on values that are of types binary-compatible with the expected argument type, not just exactly that type; for example allow citext where text is expected (Teodor Sigaev)Original release occurrence ·
9.6.0/changes/108Add variadic functions num_nulls() and num_nonnulls() that count the number of their arguments that are null or non-null Features
Add variadic functions
num_nulls()andnum_nonnulls()that count the number of their arguments that are null or non-null (Marko Tiikkaja)An example usage is CHECK(num_nonnulls(a,b,c) = 1) which asserts that exactly one of a,b,c is not NULL. These functions can also be used to count the number of null or nonnull elements in an array.
Original release occurrence ·
9.6.0/changes/109Add function parse_ident() to split a qualified, possibly quoted SQL identifier into its parts Features
Add function
parse_ident()to split a qualified, possibly quoted SQL identifier into its parts (Pavel Stehule)Original release occurrence ·
9.6.0/changes/110In to_number(), interpret a V format code as dividing by 10 to the power of the number of digits following V Features
In
to_number(), interpret a V format code as dividing by 10 to the power of the number of digits following V (Bruce Momjian)This makes it operate in an inverse fashion to
to_char().Original release occurrence ·
9.6.0/changes/111Make the to_reg*() functions accept type text not cstring Features
Make the
to_reg*()functions accept type text not cstring (Petr Korobeinikov)This avoids the need to write an explicit cast in most cases where the argument is not a simple literal constant.
Original release occurrence ·
9.6.0/changes/112Add pg_size_bytes() function to convert human-readable size strings to numbers Features
Add
pg_size_bytes()function to convert human-readable size strings to numbers (Pavel Stehule, Vitaly Burovoy, Dean Rasheed)This function converts strings like those produced by
pg_size_pretty()into bytes. An example usage is SELECT oid::regclass FROM pg_class WHERE pg_total_relation_size(oid) > pg_size_bytes('10 GB').Original release occurrence ·
9.6.0/changes/113In pg_size_pretty(), format negative numbers similarly to positive ones Features
In
pg_size_pretty(), format negative numbers similarly to positive ones (Adrian Vondendriesch)Previously, negative numbers were never abbreviated, just printed in bytes.
Original release occurrence ·
9.6.0/changes/114Add an optional missing_ok argument to the current_setting() function Features
Add an optional missing_ok argument to the
current_setting()function (David Christensen)This allows avoiding an error for an unrecognized parameter name, instead returning a NULL.
Original release occurrence ·
9.6.0/changes/115Change various catalog-inspection functions to return NULL for invalid input Features
Change various catalog-inspection functions to return NULL for invalid input (Michael Paquier)
pg_get_viewdef()now returns NULL if given an invalid view OID, and several similar functions likewise return NULL for bad input. Previously, such cases usually led to "cache lookup failed" errors, which are not meant to occur in user-facing cases.Original release occurrence ·
9.6.0/changes/116Fix pg_replication_origin_xact_reset() to not have any arguments Bug fixes
Fix
pg_replication_origin_xact_reset()to not have any arguments (Fujii Masao)The documentation said that it has no arguments, and the C code did not expect any arguments, but the entry in pg_proc mistakenly specified two arguments.
Original release occurrence ·
9.6.0/changes/117In PL/pgSQL, detect mismatched CONTINUE and EXIT statements while compiling a function, rather than at execution time Features
In PL/pgSQL, detect mismatched CONTINUE and EXIT statements while compiling a function, rather than at execution time (Jim Nasby)
Original release occurrence ·
9.6.0/changes/118Extend PL/Python's error-reporting and message-reporting functions to allow specifying additional message fields besides the primary error message Features
Extend PL/Python's error-reporting and message-reporting functions to allow specifying additional message fields besides the primary error message (Pavel Stehule)
Original release occurrence ·
9.6.0/changes/119Allow PL/Python functions to call themselves recursively via SPI, and fix the behavior when multiple set-returning PL/Python functions are called within one query Bug fixes
Allow PL/Python functions to call themselves recursively via SPI, and fix the behavior when multiple set-returning PL/Python functions are called within one query (Alexey Grishchenko, Tom Lane)
Original release occurrence ·
9.6.0/changes/120Fix session-lifespan memory leaks in PL/Python Bug fixes
Fix session-lifespan memory leaks in PL/Python (Heikki Linnakangas, Haribabu Kommi, Tom Lane)
Original release occurrence ·
9.6.0/changes/121Modernize PL/Tcl to use Tcl's "object" APIs instead of simple strings Features
Modernize PL/Tcl to use Tcl's "object" APIs instead of simple strings (Jim Nasby, Karl Lehenbauer)
This can improve performance substantially in some cases. Note that PL/Tcl now requires Tcl 8.4 or later.
Original release occurrence ·
9.6.0/changes/122In PL/Tcl, make database-reported errors return additional information in Tcl's errorCode global variable Features
In PL/Tcl, make database-reported errors return additional information in Tcl's errorCode global variable (Jim Nasby, Tom Lane)
This feature follows the Tcl convention for returning auxiliary data about an error.
Original release occurrence ·
9.6.0/changes/123Fix PL/Tcl to perform encoding conversion between the database encoding and UTF-8, which is what Tcl expects Bug fixes
Fix PL/Tcl to perform encoding conversion between the database encoding and UTF-8, which is what Tcl expects (Tom Lane)
Previously, strings were passed through without conversion, leading to misbehavior with non-ASCII characters when the database encoding was not UTF-8.
Original release occurrence ·
9.6.0/changes/124Add a nonlocalized version of the severity field in error and notice messages Features
Add a nonlocalized version of the severity field in error and notice messages (Tom Lane)
This change allows client code to determine severity of an error or notice without having to worry about localized variants of the severity strings.
Original release occurrence ·
9.6.0/changes/125Introduce a feature in libpq whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages Features
Introduce a feature in libpq whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages (Pavel Stehule)
The default behavior of
PQerrorMessage()is now to print CONTEXT only for errors. The new functionPQsetErrorContextVisibility()can be used to adjust this.Original release occurrence ·
9.6.0/changes/126Add support in libpq for regenerating an error message with a different verbosity level Features
Add support in libpq for regenerating an error message with a different verbosity level (Alex Shulgin)
This is done with the new function
PQresultVerboseErrorMessage(). This supports psql's new \errverbose feature, and may be useful for other clients as well.Original release occurrence ·
9.6.0/changes/127Improve libpq's PQhost() function to return useful data for default Unix-socket connections Features
Improve libpq's
PQhost()function to return useful data for default Unix-socket connections (Tom Lane)Previously it would return NULL if no explicit host specification had been given; now it returns the default socket directory path.
Original release occurrence ·
9.6.0/changes/128Fix ecpg's lexer to handle line breaks within comments starting on preprocessor directive lines Bug fixes
Fix ecpg's lexer to handle line breaks within comments starting on preprocessor directive lines (Michael Meskes)
Original release occurrence ·
9.6.0/changes/129Add a --strict-names option to pg_dump and pg_restore Features
Add a --strict-names option to pg_dump and pg_restore (Pavel Stehule)
This option causes the program to complain if there is no match for a -t or -n option, rather than silently doing nothing.
Original release occurrence ·
9.6.0/changes/130In pg_dump, dump locally-made changes of privilege assignments for system objects Features
In pg_dump, dump locally-made changes of privilege assignments for system objects (Stephen Frost)
While it has always been possible for a superuser to change the privilege assignments for built-in or extension-created objects, such changes were formerly lost in a dump and reload. Now, pg_dump recognizes and dumps such changes. (This works only when dumping from a 9.6 or later server, however.)
Original release occurrence ·
9.6.0/changes/131Allow pg_dump to dump non-extension-owned objects that are within an extension-owned schema Features
Allow pg_dump to dump non-extension-owned objects that are within an extension-owned schema (Martín Marqués)
Previously such objects were ignored because they were mistakenly assumed to belong to the extension owning their schema.
Original release occurrence ·
9.6.0/changes/132In pg_dump output, include the table name in object tags for object types that are only uniquely named per-table (for example, triggers) Features
In pg_dump output, include the table name in object tags for object types that are only uniquely named per-table (for example, triggers) (Peter Eisentraut)
Original release occurrence ·
9.6.0/changes/133Support multiple -c and -f command-line options Features
Support multiple -c and -f command-line options (Pavel Stehule, Catalin Iacob)
The specified operations are carried out in the order in which the options are given, and then psql terminates.
Original release occurrence ·
9.6.0/changes/134Add a \crosstabview command that prints the results of a query in a cross-tabulated display Features
Add a \crosstabview command that prints the results of a query in a cross-tabulated display (Daniel Vérité)
In the crosstab display, data values from one query result column are placed in a grid whose column and row headers come from other query result columns.
Original release occurrence ·
9.6.0/changes/135Add an \errverbose command that shows the last server error at full verbosity Features
Add an \errverbose command that shows the last server error at full verbosity (Alex Shulgin)
This is useful after getting an unexpected error — you no longer need to adjust the VERBOSITY variable and recreate the failure in order to see error fields that are not shown by default.
Original release occurrence ·
9.6.0/changes/136Add \ev and \sv commands for editing and showing view definitions Features
Add \ev and \sv commands for editing and showing view definitions (Petr Korobeinikov)
These are parallel to the existing \ef and \sf commands for functions.
Original release occurrence ·
9.6.0/changes/137Add a \gexec command that executes a query and re-submits the result(s) as new queries Features
Add a \gexec command that executes a query and re-submits the result(s) as new queries (Corey Huinker)
Original release occurrence ·
9.6.0/changes/138Allow \pset C string to set the table title, for consistency with \C string Features
Allow \pset C string to set the table title, for consistency with \C string (Bruce Momjian)
Original release occurrence ·
9.6.0/changes/139In \pset expanded auto mode, do not use expanded format for query results with only one column Features
In \pset expanded auto mode, do not use expanded format for query results with only one column (Andreas Karlsson, Robert Haas)
Original release occurrence ·
9.6.0/changes/140Improve the headers output by the \watch command Features
Improve the headers output by the \watch command (Michael Paquier, Tom Lane)
Include the \pset title string if one has been set, and shorten the prefabricated part of the header to be timestamp (every Ns). Also, the timestamp format now obeys psql's locale environment.
Original release occurrence ·
9.6.0/changes/141Improve tab-completion logic to consider the entire input query, not only the current line Features
Improve tab-completion logic to consider the entire input query, not only the current line (Tom Lane)
Previously, breaking a command into multiple lines defeated any tab completion rules that needed to see words on earlier lines.
Original release occurrence ·
9.6.0/changes/142Numerous minor improvements in tab-completion behavior Features
Numerous minor improvements in tab-completion behavior (Peter Eisentraut, Vik Fearing, Kevin Grittner, Kyotaro Horiguchi, Jeff Janes, Andreas Karlsson, Fujii Masao, Thomas Munro, Masahiko Sawada, Pavel Stehule)
Original release occurrence ·
9.6.0/changes/143Add a PROMPT option %p to insert the process ID of the connected backend Features
Add a PROMPT option %p to insert the process ID of the connected backend (Julien Rouhaud)
Original release occurrence ·
9.6.0/changes/144Introduce a feature whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages Features
Introduce a feature whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages (Pavel Stehule)
Printing CONTEXT only for errors is now the default behavior. This can be changed by setting the special variable SHOW_CONTEXT.
Original release occurrence ·
9.6.0/changes/145Make \df+ show function access privileges and parallel-safety attributes Features
Make \df+ show function access privileges and parallel-safety attributes (Michael Paquier)
Original release occurrence ·
9.6.0/changes/146SQL commands in pgbench scripts are now ended by semicolons, not newlines Features
SQL commands in pgbench scripts are now ended by semicolons, not newlines (Kyotaro Horiguchi, Tom Lane)
This change allows SQL commands in scripts to span multiple lines. Existing custom scripts will need to be modified to add a semicolon at the end of each line that does not have one already. (Doing so does not break the script for use with older versions of pgbench.)
Original release occurrence ·
9.6.0/changes/147Support floating-point arithmetic, as well as some built-in functions, in expressions in backslash commands Features
Support floating-point arithmetic, as well as some built-in functions, in expressions in backslash commands (Fabien Coelho)
Original release occurrence ·
9.6.0/changes/148Replace \setrandom with built-in functions Features
Replace \setrandom with built-in functions (Fabien Coelho)
The new built-in functions include
random(),random_exponential(), andrandom_gaussian(), which perform the same work as \setrandom, but are easier to use since they can be embedded in larger expressions. Since these additions have made \setrandom obsolete, remove it.Original release occurrence ·
9.6.0/changes/149Allow invocation of multiple copies of the built-in scripts, not only custom scripts Features
Allow invocation of multiple copies of the built-in scripts, not only custom scripts (Fabien Coelho)
This is done with the new -b switch, which works similarly to -f for custom scripts.
Original release occurrence ·
9.6.0/changes/150Allow changing the selection probabilities (weights) for scripts Features
Allow changing the selection probabilities (weights) for scripts (Fabien Coelho)
When multiple scripts are specified, each pgbench transaction randomly chooses one to execute. Formerly this was always done with uniform probability, but now different selection probabilities can be specified for different scripts.
Original release occurrence ·
9.6.0/changes/151Collect statistics for each script in a multi-script run Features
Collect statistics for each script in a multi-script run (Fabien Coelho)
This feature adds an intermediate level of detail to existing global and per-command statistics printouts.
Original release occurrence ·
9.6.0/changes/152Add a --progress-timestamp option to report progress with Unix epoch timestamps, instead of time since the run started Features
Add a --progress-timestamp option to report progress with Unix epoch timestamps, instead of time since the run started (Fabien Coelho)
Original release occurrence ·
9.6.0/changes/153Allow the number of client connections (-c) to not be an exact multiple of the number of threads (-j) Features
Allow the number of client connections (-c) to not be an exact multiple of the number of threads (-j) (Fabien Coelho)
Original release occurrence ·
9.6.0/changes/154When the -T option is used, stop promptly at the end of the specified time Features
When the -T option is used, stop promptly at the end of the specified time (Fabien Coelho)
Previously, specifying a low transaction rate could cause pgbench to wait significantly longer than specified.
Original release occurrence ·
9.6.0/changes/155Improve error reporting during initdb's post-bootstrap phase Features
Improve error reporting during initdb's post-bootstrap phase (Tom Lane)
Previously, an error here led to reporting the entire input file as the "failing query"; now just the current query is reported. To get the desired behavior, queries in initdb's input files must be separated by blank lines.
Original release occurrence ·
9.6.0/changes/156Speed up initdb by using just one standalone-backend session for all the post-bootstrap steps Performance
Speed up initdb by using just one standalone-backend session for all the post-bootstrap steps (Tom Lane)
Original release occurrence ·
9.6.0/changes/157Improve pg_rewind so that it can work when the target timeline changes Features
Improve pg_rewind so that it can work when the target timeline changes (Alexander Korotkov)
This allows, for example, rewinding a promoted standby back to some state of the old master's timeline.
Original release occurrence ·
9.6.0/changes/158Remove obsolete heap_formtuple/heap_modifytuple/heap_deformtuple functions Features
Remove obsolete
heap_formtuple/heap_modifytuple/heap_deformtuplefunctions (Peter Geoghegan)Original release occurrence ·
9.6.0/changes/159Add macros to make AllocSetContextCreate() calls simpler and safer Features
Add macros to make
AllocSetContextCreate()calls simpler and safer (Tom Lane)Writing out the individual sizing parameters for a memory context is now deprecated in favor of using one of the new macros ALLOCSET_DEFAULT_SIZES, ALLOCSET_SMALL_SIZES, or ALLOCSET_START_SMALL_SIZES. Existing code continues to work, however.
Original release occurrence ·
9.6.0/changes/160Unconditionally use static inline functions in header files Features
Unconditionally use static inline functions in header files (Andres Freund)
This may result in warnings and/or wasted code space with very old compilers, but the notational improvement seems worth it.
Original release occurrence ·
9.6.0/changes/161Improve TAP testing infrastructure Features
Improve TAP testing infrastructure (Michael Paquier, Craig Ringer, Álvaro Herrera, Stephen Frost)
Notably, it is now possible to test recovery scenarios using this infrastructure.
Original release occurrence ·
9.6.0/changes/162Make trace_lwlocks identify individual locks by name Features
Make trace_lwlocks identify individual locks by name (Robert Haas)
Original release occurrence ·
9.6.0/changes/163Improve psql's tab-completion code infrastructure Features
Improve psql's tab-completion code infrastructure (Thomas Munro, Michael Paquier)
Tab-completion rules are now considerably easier to write, and more compact.
Original release occurrence ·
9.6.0/changes/164Nail the pg_shseclabel system catalog into cache, so that it is available for access during connection authentication Features
Nail the pg_shseclabel system catalog into cache, so that it is available for access during connection authentication (Adam Brightwell)
The core code does not use this catalog for authentication, but extensions might wish to consult it.
Original release occurrence ·
9.6.0/changes/165Restructure index access method API to hide most of it at the C level Features
Restructure index access method API to hide most of it at the C level (Alexander Korotkov, Andrew Gierth)
This change modernizes the index AM API to look more like the designs we have adopted for foreign data wrappers and tablesample handlers. This simplifies the C code and makes it much more practical to define index access methods in installable extensions. A consequence is that most of the columns of the pg_am system catalog have disappeared. New inspection functions have been added to allow SQL queries to determine index AM properties that used to be discoverable from pg_am.
Original release occurrence ·
9.6.0/changes/166Add pg_init_privs system catalog to hold original privileges of initdb-created and extension-created objects Features
Add pg_init_privs system catalog to hold original privileges of initdb-created and extension-created objects (Stephen Frost)
This infrastructure allows pg_dump to dump changes that an installation may have made in privileges attached to system objects. Formerly, such changes would be lost in a dump and reload, but now they are preserved.
Original release occurrence ·
9.6.0/changes/167Change the way that extensions allocate custom LWLocks Features
Change the way that extensions allocate custom LWLocks (Amit Kapila, Robert Haas)
The
RequestAddinLWLocks()function is removed, and replaced byRequestNamedLWLockTranche(). This allows better identification of custom LWLocks, and is less error-prone.Original release occurrence ·
9.6.0/changes/168Improve the isolation tester to allow multiple sessions to wait concurrently, allowing testing of deadlock scenarios Features
Improve the isolation tester to allow multiple sessions to wait concurrently, allowing testing of deadlock scenarios (Robert Haas)
Original release occurrence ·
9.6.0/changes/169Introduce extensible node types Features
Introduce extensible node types (KaiGai Kohei)
This change allows FDWs or custom scan providers to store data in a plan tree in a more convenient format than was previously possible.
Original release occurrence ·
9.6.0/changes/170Make the planner deal with post-scan/join query steps by generating and comparing Paths, replacing a lot of ad-hoc logic Features
Make the planner deal with post-scan/join query steps by generating and comparing Paths, replacing a lot of ad-hoc logic (Tom Lane)
This change provides only marginal user-visible improvements today, but it enables future work on a lot of upper-planner improvements that were impractical to tackle using the old code structure.
Original release occurrence ·
9.6.0/changes/171Support partial aggregation Features
Support partial aggregation (David Rowley, Simon Riggs)
This change allows the computation of an aggregate function to be split into separate parts, for example so that parallel worker processes can cooperate on computing an aggregate. In future it might allow aggregation across local and remote data to occur partially on the remote end.
Original release occurrence ·
9.6.0/changes/172Add a generic command progress reporting facility Features
Add a generic command progress reporting facility (Vinayak Pokale, Rahila Syed, Amit Langote, Robert Haas)
Original release occurrence ·
9.6.0/changes/173Separate out psql's flex lexer to make it usable by other client programs Features
Separate out psql's flex lexer to make it usable by other client programs (Tom Lane, Kyotaro Horiguchi)
This eliminates code duplication for programs that need to be able to parse SQL commands well enough to identify command boundaries. Doing that in full generality is more painful than one could wish, and up to now only psql has really gotten it right among our supported client programs.
A new source-code subdirectory src/fe_utils/ has been created to hold this and other code that is shared across our client programs. Formerly such sharing was accomplished by symbolic linking or copying source files at build time, which was ugly and required duplicate compilation.
Original release occurrence ·
9.6.0/changes/174Introduce WaitEventSet API to allow efficient waiting for event sets that usually do not change from one wait to the next Features
Introduce WaitEventSet API to allow efficient waiting for event sets that usually do not change from one wait to the next (Andres Freund, Amit Kapila)
Original release occurrence ·
9.6.0/changes/175Add a generic interface for writing WAL records Features
Add a generic interface for writing WAL records (Alexander Korotkov, Petr Jelínek, Markus Nullmeier)
This change allows extensions to write WAL records for changes to pages using a standard layout. The problem of needing to replay WAL without access to the extension is solved by having generic replay code. This allows extensions to implement, for example, index access methods and have WAL support for them.
Original release occurrence ·
9.6.0/changes/176Support generic WAL messages for logical decoding Features
Support generic WAL messages for logical decoding (Petr Jelínek, Andres Freund)
This feature allows extensions to insert data into the WAL stream that can be read by logical-decoding plugins, but is not connected to physical data restoration.
Original release occurrence ·
9.6.0/changes/177Allow SP-GiST operator classes to store an arbitrary "traversal value" while descending the index Features
Allow SP-GiST operator classes to store an arbitrary "traversal value" while descending the index (Alexander Lebedev, Teodor Sigaev)
This is somewhat like the "reconstructed value", but it could be any arbitrary chunk of data, not necessarily of the same data type as the indexed column.
Original release occurrence ·
9.6.0/changes/178Introduce a LOG_SERVER_ONLY message level for ereport() Features
Introduce a LOG_SERVER_ONLY message level for
ereport()(David Steele)This level acts like LOG except that the message is never sent to the client. It is meant for use in auditing and similar applications.
Original release occurrence ·
9.6.0/changes/179Provide a Makefile target to build all generated headers Features
Provide a Makefile target to build all generated headers (Michael Paquier, Tom Lane)
submake-generated-headers can now be invoked to ensure that generated backend header files are up-to-date. This is useful in subdirectories that might be built "standalone".
Original release occurrence ·
9.6.0/changes/180Support OpenSSL 1.1.0 Features
Support OpenSSL 1.1.0 (Andreas Karlsson, Heikki Linnakangas)
Original release occurrence ·
9.6.0/changes/181Add configuration parameter auto_explain.sample_rate to allow contrib/auto_explain to capture just a configurable fraction of all queries Features
Add configuration parameter auto_explain.sample_rate to allow contrib/auto_explain to capture just a configurable fraction of all queries (Craig Ringer, Julien Rouhaud)
This allows reduction of overhead for heavy query traffic, while still getting useful information on average.
Original release occurrence ·
9.6.0/changes/182Add contrib/bloom module that implements an index access method based on Bloom filtering Features
Add contrib/bloom module that implements an index access method based on Bloom filtering (Teodor Sigaev, Alexander Korotkov)
This is primarily a proof-of-concept for non-core index access methods, but it could be useful in its own right for queries that search many columns.
Original release occurrence ·
9.6.0/changes/183In contrib/cube, introduce distance operators for cubes, and support kNN-style searches in GiST indexes on cube columns Features
In contrib/cube, introduce distance operators for cubes, and support kNN-style searches in GiST indexes on cube columns (Stas Kelvich)
Original release occurrence ·
9.6.0/changes/184Make contrib/hstore's hstore_to_jsonb_loose() and hstore_to_json_loose() functions agree on what is a number Features
Make contrib/hstore's
hstore_to_jsonb_loose()andhstore_to_json_loose()functions agree on what is a number (Tom Lane)Previously,
hstore_to_jsonb_loose()would convert numeric-looking strings to JSON numbers, rather than strings, even if they did not exactly match the JSON syntax specification for numbers. This was inconsistent withhstore_to_json_loose(), so tighten the test to match the JSON syntax.Original release occurrence ·
9.6.0/changes/185Add selectivity estimation functions for contrib/intarray operators to improve plans for queries using those operators Features
Add selectivity estimation functions for contrib/intarray operators to improve plans for queries using those operators (Yury Zhuravlev, Alexander Korotkov)
Original release occurrence ·
9.6.0/changes/186Make contrib/pageinspect's heap_page_items() function show the raw data in each tuple, and add new functions tuple_data_split() and heap_page_item_attrs() for inspection of individual tuple fields Features
Make contrib/pageinspect's
heap_page_items()function show the raw data in each tuple, and add new functionstuple_data_split()andheap_page_item_attrs()for inspection of individual tuple fields (Nikolay Shaplov)Original release occurrence ·
9.6.0/changes/187Add an optional S2K iteration count parameter to contrib/pgcrypto's pgp_sym_encrypt() function Features
Add an optional S2K iteration count parameter to contrib/pgcrypto's
pgp_sym_encrypt()function (Jeff Janes)Original release occurrence ·
9.6.0/changes/188Add support for "word similarity" to contrib/pg_trgm Features
Add support for "word similarity" to contrib/pg_trgm (Alexander Korotkov, Artur Zakirov)
These functions and operators measure the similarity between one string and the most similar single word of another string.
Original release occurrence ·
9.6.0/changes/189Add configuration parameter pg_trgm.similarity_threshold for contrib/pg_trgm's similarity threshold Features
Add configuration parameter pg_trgm.similarity_threshold for contrib/pg_trgm's similarity threshold (Artur Zakirov)
This threshold has always been configurable, but formerly it was controlled by special-purpose functions
set_limit()andshow_limit(). Those are now deprecated.Original release occurrence ·
9.6.0/changes/190Improve contrib/pg_trgm's GIN operator class to speed up index searches in which both common and rare keys appear Performance
Improve contrib/pg_trgm's GIN operator class to speed up index searches in which both common and rare keys appear (Jeff Janes)
Original release occurrence ·
9.6.0/changes/191Improve performance of similarity searches in contrib/pg_trgm GIN indexes Performance
Improve performance of similarity searches in contrib/pg_trgm GIN indexes (Christophe Fornaroli)
Original release occurrence ·
9.6.0/changes/192Add contrib/pg_visibility module to allow examining table visibility maps Features
Add contrib/pg_visibility module to allow examining table visibility maps (Robert Haas)
Original release occurrence ·
9.6.0/changes/193Add ssl_extension_info() function to contrib/sslinfo, to print information about SSL extensions present in the X509 certificate used for the current connection Features
Add
ssl_extension_info()function to contrib/sslinfo, to print information about SSL extensions present in the X509 certificate used for the current connection (Dmitry Voronin)Original release occurrence ·
9.6.0/changes/194Allow extension-provided operators and functions to be sent for remote execution, if the extension is whitelisted in the foreign server's options Features
Allow extension-provided operators and functions to be sent for remote execution, if the extension is whitelisted in the foreign server's options (Paul Ramsey)
Users can enable this feature when the extension is known to exist in a compatible version in the remote database. It allows more efficient execution of queries involving extension operators.
Original release occurrence ·
9.6.0/changes/195Consider performing sorts on the remote server Features
Consider performing sorts on the remote server (Ashutosh Bapat)
Original release occurrence ·
9.6.0/changes/196Consider performing joins on the remote server Features
Consider performing joins on the remote server (Shigeru Hanada, Ashutosh Bapat)
Original release occurrence ·
9.6.0/changes/197When feasible, perform UPDATE or DELETE entirely on the remote server Features
When feasible, perform UPDATE or DELETE entirely on the remote server (Etsuro Fujita)
Formerly, remote updates involved sending a SELECT FOR UPDATE command and then updating or deleting the selected rows one-by-one. While that is still necessary if the operation requires any local processing, it can now be done remotely if all elements of the query are safe to send to the remote server.
Original release occurrence ·
9.6.0/changes/198Allow the fetch size to be set as a server or table option Features
Allow the fetch size to be set as a server or table option (Corey Huinker)
Formerly, postgres_fdw always fetched 100 rows at a time from remote queries; now that behavior is configurable.
Original release occurrence ·
9.6.0/changes/199Use a single foreign-server connection for local user IDs that all map to the same remote user Features
Use a single foreign-server connection for local user IDs that all map to the same remote user (Ashutosh Bapat)
Original release occurrence ·
9.6.0/changes/200Transmit query cancellation requests to the remote server Features
Transmit query cancellation requests to the remote server (Michael Paquier, Etsuro Fujita)
Previously, a local query cancellation request did not cause an already-sent remote query to terminate early.
Original release occurrence ·
9.6.0/changes/201
Security evidence
34 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2021-3449 · CVE-2021-3449
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 9.6.22. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 9.6.22. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 9.6.24. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 9.6.24. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 9.6.20. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 9.6.20. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 9.6.20. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1
The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 9.6.17. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1
When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 9.6.19. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7
The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.
Fixed in this branch: 9.6.18. Component: packaging.
Official affected-branch entry: 9.6.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4
A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.
Fixed in this branch: 9.6.16. Component: packaging.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8
When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.
Fixed in this branch: 9.6.15. Component: packaging.
Official affected-branch entry: 9.6.
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7
The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 9.6.15. Component: packaging.
Official affected-branch entry: 9.6.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 9.6.15. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1
PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
Fixed in this branch: 9.6.13. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 9.6.13. Component: packaging.
Official affected-branch entry: 9.6.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0
Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.
Fixed in this branch: 9.6.13. Component: packaging.
Official affected-branch entry: 9.6.
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-1115 · Too-permissive access control list on function pg_logfile_rotate() CVSS 3.1
Fixed in this branch: 9.6.9. Component: contrib module.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. CVSS 7.1
Fixed in this branch: 9.6.10. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Release-note mentions:
CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5
Fixed in this branch: 9.6.10. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
Fixed in this branch: 9.6.8. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7
Fixed in this branch: 9.6.7. Component: client.
Official affected-branch entry: 9.6.
AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7548 · lo_put() function ignores ACLs CVSS 3.1
Fixed in this branch: 9.6.4. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges CVSS 8.5
Fixed in this branch: 9.6.4. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7546 · empty password accepted in some authentication methods CVSS 8.1
Fixed in this branch: 9.6.4. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords CVSS 8.5
Fixed in this branch: 9.6.3. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable CVSS 8.1
Fixed in this branch: 9.6.3. Component: client.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
Fixed in this branch: 9.6.3. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVSS 3.1
Fixed in this branch: 9.6.6. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3
Fixed in this branch: 9.6.6. Component: core server.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4
Fixed in this branch: 9.6.6. Component: contrib module.
Official affected-branch entry: 9.6.
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Release-note mentions:
CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases