↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 9.6

Read the English manual

End of life · Recorded build 9.6.24 · 2021-11-11

This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.

First stable release
2016-09-29
Support end
2021-11-11
Indexed releases
25
Original release-note entries
1105

Manuals & provenance

PostgreSQL 9.6 English manual · 1046 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 9.6.0 · Changes from the initial release through 9.6.24

Original migration guidance for 9.6.0

A dump/restore using pg_dumpall, or use of pg_upgrade, is required for those wishing to migrate data from any previous release.

Version 9.6 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
9.6.24 2021-11-11 401802
9.6.23 2021-08-12 471602
9.6.22 2021-05-13 231302
9.6.21 2021-02-11 361800
9.6.20 2020-11-12 361003
9.6.19 2020-08-13 271302
9.6.18 2020-05-14 381800
9.6.17 2020-02-13 331701
9.6.16 2019-11-14 532100
9.6.15 2019-08-08 261002
9.6.14 2019-06-20 171100
9.6.13 2019-05-09 331802
9.6.12 2019-02-14 442400
9.6.11 2018-11-08 572700
9.6.10 2018-08-09 331702
9.6.9 2018-05-10 432401
9.6.8 2018-03-01 8401
9.6.7 2018-02-08 372001
9.6.6 2017-11-09 382003
9.6.5 2017-08-31 10300
9.6.4 2017-08-10 603004
9.6.3 2017-05-11 483004
9.6.2 2017-02-09 764700
9.6.1 2016-10-27 281700
9.6.0 2016-09-29 2146130

Initial release changes

Original entries from 9.6.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

214 of 214 original entries.

  • Improve the pg_stat_activity view's information about what a process is waiting for Compatibility Migration

    Improve the pg_stat_activity view's information about what a process is waiting for (Amit Kapila, Ildus Kurbangaliev)

    Historically a process has only been shown as waiting if it was waiting for a heavyweight lock. Now waits for lightweight locks and buffer pins are also shown in pg_stat_activity. Also, the type of lock being waited for is now visible. These changes replace the waiting column with wait_event_type and wait_event.

    Original release occurrence · 9.6.0/migration/001

  • In to_char(), do not count a minus sign (when needed) as part of the field width for time-related fields Compatibility Migration

    In to_char(), do not count a minus sign (when needed) as part of the field width for time-related fields (Bruce Momjian)

    For example, to_char('-4 years'::interval, 'YY') now returns -04, rather than -4.

    Original release occurrence · 9.6.0/migration/002

  • Make extract() behave more reasonably with infinite inputs Compatibility Migration

    Make extract() behave more reasonably with infinite inputs (Vitaly Burovoy)

    Historically the extract() function just returned zero given an infinite timestamp, regardless of the given field name. Make it return infinity or -infinity as appropriate when the requested field is one that is monotonically increasing (e.g, year, epoch), or NULL when it is not (e.g., day, hour). Also, throw the expected error for bad field names.

    Original release occurrence · 9.6.0/migration/003

  • Remove PL/pgSQL's "feature" that suppressed the innermost line of CONTEXT for messages emitted by RAISE commands Compatibility Migration

    Remove PL/pgSQL's "feature" that suppressed the innermost line of CONTEXT for messages emitted by RAISE commands (Pavel Stehule)

    This ancient backwards-compatibility hack was agreed to have outlived its usefulness.

    Original release occurrence · 9.6.0/migration/004

  • Fix the default text search parser to allow leading digits in email and host tokens Compatibility Migration

    Fix the default text search parser to allow leading digits in email and host tokens (Artur Zakirov)

    In most cases this will result in few changes in the parsing of text. But if you have data where such addresses occur frequently, it may be worth rebuilding dependent tsvector columns and indexes so that addresses of this form will be found properly by text searches.

    Original release occurrence · 9.6.0/migration/005

  • Extend contrib/unaccent's standard unaccent.rules file to handle all diacritics known to Unicode, and to expand ligatures correctly Compatibility Migration

    Extend contrib/unaccent's standard unaccent.rules file to handle all diacritics known to Unicode, and to expand ligatures correctly (Thomas Munro, Léonard Benedetti)

    The previous version neglected to convert some less-common letters with diacritic marks. Also, ligatures are now expanded into separate letters. Installations that use this rules file may wish to rebuild tsvector columns and indexes that depend on the result.

    Original release occurrence · 9.6.0/migration/006

  • Remove the long-deprecated CREATEUSER/NOCREATEUSER options from CREATE ROLE and allied commands Compatibility Migration

    Remove the long-deprecated CREATEUSER/NOCREATEUSER options from CREATE ROLE and allied commands (Tom Lane)

    CREATEUSER actually meant SUPERUSER, for ancient backwards-compatibility reasons. This has been a constant source of confusion for people who (reasonably) expect it to mean CREATEROLE. It has been deprecated for ten years now, so fix the problem by removing it.

    Original release occurrence · 9.6.0/migration/007

  • Treat role names beginning with pg_ as reserved Compatibility Migration

    Treat role names beginning with pg_ as reserved (Stephen Frost)

    User creation of such role names is now disallowed. This prevents conflicts with built-in roles created by initdb.

    Original release occurrence · 9.6.0/migration/008

  • Change a column name in the information_schema.routines view from result_cast_character_set_name to result_cast_char_set_name Compatibility Migration

    Change a column name in the information_schema.routines view from result_cast_character_set_name to result_cast_char_set_name (Clément Prévost)

    The SQL:2011 standard specifies the longer name, but that appears to be a mistake, because adjacent column names use the shorter style, as do other information_schema views.

    Original release occurrence · 9.6.0/migration/009

  • psql's -c option no longer implies --no-psqlrc Compatibility Migration

    psql's -c option no longer implies --no-psqlrc (Pavel Stehule, Catalin Iacob)

    Write --no-psqlrc (or its abbreviation -X) explicitly to obtain the old behavior. Scripts so modified will still work with old versions of psql.

    Original release occurrence · 9.6.0/migration/010

  • Improve pg_restore's -t option to match all types of relations, not only plain tables Compatibility Migration

    Improve pg_restore's -t option to match all types of relations, not only plain tables (Craig Ringer)

    Original release occurrence · 9.6.0/migration/011

  • Change the display format used for NextXID in pg_controldata and related places Compatibility Migration

    Change the display format used for NextXID in pg_controldata and related places (Joe Conway, Bruce Momjian)

    Display epoch-and-transaction-ID values in the format number:number. The previous format number/number was confusingly similar to that used for LSNs.

    Original release occurrence · 9.6.0/migration/012

  • Update extension functions to be marked parallel-safe where appropriate Compatibility Migration

    Update extension functions to be marked parallel-safe where appropriate (Andreas Karlsson)

    Many of the standard extensions have been updated to allow their functions to be executed within parallel query worker processes. These changes will not take effect in databases pg_upgrade'd from prior versions unless you apply ALTER EXTENSION UPDATE to each such extension (in each database of a cluster).

    Original release occurrence · 9.6.0/migration/013

  • Parallel queries Features

    Parallel queries (Robert Haas, Amit Kapila, David Rowley, many others)

    With 9.6, PostgreSQL introduces initial support for parallel execution of large queries. Only strictly read-only queries where the driving table is accessed via a sequential scan can be parallelized. Hash joins and nested loops can be performed in parallel, as can aggregation (for supported aggregates). Much remains to be done, but this is already a useful set of features.

    Parallel query execution is not (yet) enabled by default. To allow it, set the new configuration parameter max_parallel_workers_per_gather to a value larger than zero. Additional control over use of parallelism is available through other new configuration parameters force_parallel_mode, parallel_setup_cost, parallel_tuple_cost, and min_parallel_relation_size.

    Original release occurrence · 9.6.0/changes/001

  • Provide infrastructure for marking the parallel-safety status of functions Features

    Provide infrastructure for marking the parallel-safety status of functions (Robert Haas, Amit Kapila)

    Original release occurrence · 9.6.0/changes/002

  • Allow GIN index builds to make effective use of maintenance_work_mem settings larger than 1 GB Features

    Allow GIN index builds to make effective use of maintenance_work_mem settings larger than 1 GB (Robert Abraham, Teodor Sigaev)

    Original release occurrence · 9.6.0/changes/003

  • Add pages deleted from a GIN index's pending list to the free space map immediately Features

    Add pages deleted from a GIN index's pending list to the free space map immediately (Jeff Janes, Teodor Sigaev)

    This reduces bloat if the table is not vacuumed often.

    Original release occurrence · 9.6.0/changes/004

  • Add gin_clean_pending_list() function to allow manual invocation of pending-list cleanup for a GIN index Features

    Add gin_clean_pending_list() function to allow manual invocation of pending-list cleanup for a GIN index (Jeff Janes)

    Formerly, such cleanup happened only as a byproduct of vacuuming or analyzing the parent table.

    Original release occurrence · 9.6.0/changes/005

  • Improve handling of dead index tuples in GiST indexes Features

    Improve handling of dead index tuples in GiST indexes (Anastasia Lubennikova)

    Dead index tuples are now marked as such when an index scan notices that the corresponding heap tuple is dead. When inserting tuples, marked-dead tuples will be removed if needed to make space on the page.

    Original release occurrence · 9.6.0/changes/006

  • Add an SP-GiST operator class for type box Features

    Add an SP-GiST operator class for type box (Alexander Lebedev)

    Original release occurrence · 9.6.0/changes/007

  • Improve sorting performance by using quicksort, not replacement selection sort, when performing external sort steps Performance

    Improve sorting performance by using quicksort, not replacement selection sort, when performing external sort steps (Peter Geoghegan)

    The new approach makes better use of the CPU cache for typical cache sizes and data volumes. Where necessary, the behavior can be adjusted via the new configuration parameter replacement_sort_tuples.

    Original release occurrence · 9.6.0/changes/008

  • Speed up text sorts where the same string occurs multiple times Performance

    Speed up text sorts where the same string occurs multiple times (Peter Geoghegan)

    Original release occurrence · 9.6.0/changes/009

  • Speed up sorting of uuid, bytea, and char(n) fields by using "abbreviated" keys Performance

    Speed up sorting of uuid, bytea, and char(n) fields by using "abbreviated" keys (Peter Geoghegan)

    Support for abbreviated keys has also been added to the non-default operator classes text_pattern_ops, varchar_pattern_ops, and bpchar_pattern_ops. Processing of ordered-set aggregates can also now exploit abbreviated keys.

    Original release occurrence · 9.6.0/changes/010

  • Speed up CREATE INDEX CONCURRENTLY by treating TIDs as 64-bit integers during sorting Performance

    Speed up CREATE INDEX CONCURRENTLY by treating TIDs as 64-bit integers during sorting (Peter Geoghegan)

    Original release occurrence · 9.6.0/changes/011

  • Reduce contention for the ProcArrayLock Features

    Reduce contention for the ProcArrayLock (Amit Kapila, Robert Haas)

    Original release occurrence · 9.6.0/changes/012

  • Improve performance by moving buffer content locks into the buffer descriptors Performance

    Improve performance by moving buffer content locks into the buffer descriptors (Andres Freund, Simon Riggs)

    Original release occurrence · 9.6.0/changes/013

  • Replace shared-buffer header spinlocks with atomic operations to improve scalability Features

    Replace shared-buffer header spinlocks with atomic operations to improve scalability (Alexander Korotkov, Andres Freund)

    Original release occurrence · 9.6.0/changes/014

  • Use atomic operations, rather than a spinlock, to protect an LWLock's wait queue Features

    Use atomic operations, rather than a spinlock, to protect an LWLock's wait queue (Andres Freund)

    Original release occurrence · 9.6.0/changes/015

  • Partition the shared hash table freelist to reduce contention on multi-CPU-socket servers Features

    Partition the shared hash table freelist to reduce contention on multi-CPU-socket servers (Aleksander Alekseev)

    Original release occurrence · 9.6.0/changes/016

  • Reduce interlocking on standby servers during the replay of btree index vacuuming operations Features

    Reduce interlocking on standby servers during the replay of btree index vacuuming operations (Simon Riggs)

    This change avoids substantial replication delays that sometimes occurred while replaying such operations.

    Original release occurrence · 9.6.0/changes/017

  • Improve ANALYZE's estimates for columns with many nulls Features

    Improve ANALYZE's estimates for columns with many nulls (Tomas Vondra, Alex Shulgin)

    Previously ANALYZE tended to underestimate the number of non-NULL distinct values in a column with many NULLs, and was also inaccurate in computing the most-common values.

    Original release occurrence · 9.6.0/changes/018

  • Improve planner's estimate of the number of distinct values in a query result Features

    Improve planner's estimate of the number of distinct values in a query result (Tomas Vondra)

    Original release occurrence · 9.6.0/changes/019

  • Use foreign key relationships to infer selectivity for join predicates Features

    Use foreign key relationships to infer selectivity for join predicates (Tomas Vondra, David Rowley)

    If a table t has a foreign key restriction, say (a,b) REFERENCES r (x,y), then a WHERE condition such as t.a = r.x AND t.b = r.y cannot select more than one r row per t row. The planner formerly considered these AND conditions to be independent and would often drastically misestimate selectivity as a result. Now it compares the WHERE conditions to applicable foreign key constraints and produces better estimates.

    Original release occurrence · 9.6.0/changes/020

  • Avoid re-vacuuming pages containing only frozen tuples Features

    Avoid re-vacuuming pages containing only frozen tuples (Masahiko Sawada, Robert Haas, Andres Freund)

    Formerly, anti-wraparound vacuum had to visit every page of a table, even pages where there was nothing to do. Now, pages containing only already-frozen tuples are identified in the table's visibility map, and can be skipped by vacuum even when doing transaction wraparound prevention. This should greatly reduce the cost of maintaining large tables containing mostly-unchanging data.

    If necessary, vacuum can be forced to process all-frozen pages using the new DISABLE_PAGE_SKIPPING option. Normally this should never be needed, but it might help in recovering from visibility-map corruption.

    Original release occurrence · 9.6.0/changes/021

  • Avoid useless heap-truncation attempts during VACUUM Features

    Avoid useless heap-truncation attempts during VACUUM (Jeff Janes, Tom Lane)

    This change avoids taking an exclusive table lock in some cases where no truncation is possible. The main benefit comes from avoiding unnecessary query cancellations on standby servers.

    Original release occurrence · 9.6.0/changes/022

  • Allow old MVCC snapshots to be invalidated after a configurable timeout Performance

    Allow old MVCC snapshots to be invalidated after a configurable timeout (Kevin Grittner)

    Normally, deleted tuples cannot be physically removed by vacuuming until the last transaction that could "see" them is gone. A transaction that stays open for a long time can thus cause considerable table bloat because space cannot be recycled. This feature allows setting a time-based limit, via the new configuration parameter old_snapshot_threshold, on how long an MVCC snapshot is guaranteed to be valid. After that, dead tuples are candidates for removal. A transaction using an outdated snapshot will get an error if it attempts to read a page that potentially could have contained such data.

    Original release occurrence · 9.6.0/changes/023

  • Ignore GROUP BY columns that are functionally dependent on other columns Performance

    Ignore GROUP BY columns that are functionally dependent on other columns (David Rowley)

    If a GROUP BY clause includes all columns of a non-deferred primary key, as well as other columns of the same table, those other columns are redundant and can be dropped from the grouping. This saves computation in many common cases.

    Original release occurrence · 9.6.0/changes/024

  • Allow use of an index-only scan on a partial index when the index's WHERE clause references columns that are not indexed Performance

    Allow use of an index-only scan on a partial index when the index's WHERE clause references columns that are not indexed (Tomas Vondra, Kyotaro Horiguchi)

    For example, an index defined by CREATE INDEX tidx_partial ON t(b) WHERE a > 0 can now be used for an index-only scan by a query that specifies WHERE a > 0 and does not otherwise use a. Previously this was disallowed because a is not listed as an index column.

    Original release occurrence · 9.6.0/changes/025

  • Perform checkpoint writes in sorted order Performance

    Perform checkpoint writes in sorted order (Fabien Coelho, Andres Freund)

    Previously, checkpoints wrote out dirty pages in whatever order they happen to appear in shared buffers, which usually is nearly random. That performs poorly, especially on rotating media. This change causes checkpoint-driven writes to be done in order by file and block number, and to be balanced across tablespaces.

    Original release occurrence · 9.6.0/changes/026

  • Where feasible, trigger kernel writeback after a configurable number of writes, to prevent accumulation of dirty data in kernel disk buffers Performance

    Where feasible, trigger kernel writeback after a configurable number of writes, to prevent accumulation of dirty data in kernel disk buffers (Fabien Coelho, Andres Freund)

    PostgreSQL writes data to the kernel's disk cache, from where it will be flushed to physical storage in due time. Many operating systems are not smart about managing this and allow large amounts of dirty data to accumulate before deciding to flush it all at once, causing long delays for new I/O requests until the flushing finishes. This change attempts to alleviate this problem by explicitly requesting data flushes after a configurable interval.

    On Linux, sync_file_range() is used for this purpose, and the feature is on by default on Linux because that function has few downsides. This flushing capability is also available on other platforms if they have msync() or posix_fadvise(), but those interfaces have some undesirable side-effects so the feature is disabled by default on non-Linux platforms.

    The new configuration parameters backend_flush_after, bgwriter_flush_after, checkpoint_flush_after, and wal_writer_flush_after control this behavior.

    Original release occurrence · 9.6.0/changes/027

  • Improve aggregate-function performance by sharing calculations across multiple aggregates if they have the same arguments and transition functions Performance

    Improve aggregate-function performance by sharing calculations across multiple aggregates if they have the same arguments and transition functions (David Rowley)

    For example, SELECT AVG(x), VARIANCE(x) FROM tab can use a single per-row computation for both aggregates.

    Original release occurrence · 9.6.0/changes/028

  • Speed up visibility tests for recently-created tuples by checking the current transaction's snapshot, not pg_clog, to decide if the source transaction should be considered committed Performance

    Speed up visibility tests for recently-created tuples by checking the current transaction's snapshot, not pg_clog, to decide if the source transaction should be considered committed (Jeff Janes, Tom Lane)

    Original release occurrence · 9.6.0/changes/029

  • Allow tuple hint bits to be set sooner than before Performance

    Allow tuple hint bits to be set sooner than before (Andres Freund)

    Original release occurrence · 9.6.0/changes/030

  • Improve performance of short-lived prepared transactions Performance

    Improve performance of short-lived prepared transactions (Stas Kelvich, Simon Riggs, Pavan Deolasee)

    Two-phase commit information is now written only to WAL during PREPARE TRANSACTION, and will be read back from WAL during COMMIT PREPARED if that happens soon thereafter. A separate state file is created only if the pending transaction does not get committed or aborted by the time of the next checkpoint.

    Original release occurrence · 9.6.0/changes/031

  • Improve performance of memory context destruction Performance

    Improve performance of memory context destruction (Jan Wieck)

    Original release occurrence · 9.6.0/changes/032

  • Improve performance of resource owners with many tracked objects Performance

    Improve performance of resource owners with many tracked objects (Aleksander Alekseev)

    Original release occurrence · 9.6.0/changes/033

  • Improve speed of the output functions for timestamp, time, and date data types Performance

    Improve speed of the output functions for timestamp, time, and date data types (David Rowley, Andres Freund)

    Original release occurrence · 9.6.0/changes/034

  • Avoid some unnecessary cancellations of hot-standby queries during replay of actions that take AccessExclusive locks Performance

    Avoid some unnecessary cancellations of hot-standby queries during replay of actions that take AccessExclusive locks (Jeff Janes)

    Original release occurrence · 9.6.0/changes/035

  • Extend relations multiple blocks at a time when there is contention for the relation's extension lock Performance

    Extend relations multiple blocks at a time when there is contention for the relation's extension lock (Dilip Kumar)

    This improves scalability by decreasing contention.

    Original release occurrence · 9.6.0/changes/036

  • Increase the number of clog buffers for better scalability Performance

    Increase the number of clog buffers for better scalability (Amit Kapila, Andres Freund)

    Original release occurrence · 9.6.0/changes/037

  • Speed up expression evaluation in PL/pgSQL by keeping ParamListInfo entries for simple variables valid at all times Performance

    Speed up expression evaluation in PL/pgSQL by keeping ParamListInfo entries for simple variables valid at all times (Tom Lane)

    Original release occurrence · 9.6.0/changes/038

  • Avoid reducing the SO_SNDBUF setting below its default on recent Windows versions Performance

    Avoid reducing the SO_SNDBUF setting below its default on recent Windows versions (Chen Huajun)

    Original release occurrence · 9.6.0/changes/039

  • Disable update_process_title by default on Windows Performance

    Disable update_process_title by default on Windows (Takayuki Tsunakawa)

    The overhead of updating the process title is much larger on Windows than most other platforms, and it is also less useful to do it since most Windows users do not have tools that can display process titles.

    Original release occurrence · 9.6.0/changes/040

  • Add pg_stat_progress_vacuum system view to provide progress reporting for VACUUM operations Features

    Add pg_stat_progress_vacuum system view to provide progress reporting for VACUUM operations (Amit Langote, Robert Haas, Vinayak Pokale, Rahila Syed)

    Original release occurrence · 9.6.0/changes/041

  • Add pg_control_system(), pg_control_checkpoint(), pg_control_recovery(), and pg_control_init() functions to expose fields of pg_control to SQL Features

    Add pg_control_system(), pg_control_checkpoint(), pg_control_recovery(), and pg_control_init() functions to expose fields of pg_control to SQL (Joe Conway, Michael Paquier)

    Original release occurrence · 9.6.0/changes/042

  • Add pg_config system view Features

    Add pg_config system view (Joe Conway)

    This view exposes the same information available from the pg_config command-line utility, namely assorted compile-time configuration information for PostgreSQL.

    Original release occurrence · 9.6.0/changes/043

  • Add a confirmed_flush_lsn column to the pg_replication_slots system view Features

    Add a confirmed_flush_lsn column to the pg_replication_slots system view (Marko Tiikkaja)

    Original release occurrence · 9.6.0/changes/044

  • Add pg_stat_wal_receiver system view to provide information about the state of a hot-standby server's WAL receiver process Features

    Add pg_stat_wal_receiver system view to provide information about the state of a hot-standby server's WAL receiver process (Michael Paquier)

    Original release occurrence · 9.6.0/changes/045

  • Add pg_blocking_pids() function to reliably identify which sessions block which others Features

    Add pg_blocking_pids() function to reliably identify which sessions block which others (Tom Lane)

    This function returns an array of the process IDs of any sessions that are blocking the session with the given process ID. Historically users have obtained such information using a self-join on the pg_locks view. However, it is unreasonably tedious to do it that way with any modicum of correctness, and the addition of parallel queries has made the old approach entirely impractical, since locks might be held or awaited by child worker processes rather than the session's main process.

    Original release occurrence · 9.6.0/changes/046

  • Add function pg_current_xlog_flush_location() to expose the current transaction log flush location Features

    Add function pg_current_xlog_flush_location() to expose the current transaction log flush location (Tomas Vondra)

    Original release occurrence · 9.6.0/changes/047

  • Add function pg_notification_queue_usage() to report how full the NOTIFY queue is Features

    Add function pg_notification_queue_usage() to report how full the NOTIFY queue is (Brendan Jurd)

    Original release occurrence · 9.6.0/changes/048

  • Limit the verbosity of memory context statistics dumps Features

    Limit the verbosity of memory context statistics dumps (Tom Lane)

    The memory usage dump that is output to the postmaster log during an out-of-memory failure now summarizes statistics when there are a large number of memory contexts, rather than possibly generating a very large report. There is also a "grand total" summary line now.

    Original release occurrence · 9.6.0/changes/049

  • Add a BSD authentication method to allow use of the BSD Authentication service for PostgreSQL client authentication Features

    Add a BSD authentication method to allow use of the BSD Authentication service for PostgreSQL client authentication (Marisa Emerson)

    BSD Authentication is currently only available on OpenBSD.

    Original release occurrence · 9.6.0/changes/050

  • When using PAM authentication, provide the client IP address or host name to PAM modules via the PAM_RHOST item Features

    When using PAM authentication, provide the client IP address or host name to PAM modules via the PAM_RHOST item (Grzegorz Sampolski)

    Original release occurrence · 9.6.0/changes/051

  • Provide detail in the postmaster log for more types of password authentication failure Features

    Provide detail in the postmaster log for more types of password authentication failure (Tom Lane)

    All ordinarily-reachable password authentication failure cases should now provide specific DETAIL fields in the log.

    Original release occurrence · 9.6.0/changes/052

  • Support RADIUS passwords up to 128 characters long Features

    Support RADIUS passwords up to 128 characters long (Marko Tiikkaja)

    Original release occurrence · 9.6.0/changes/053

  • Add new SSPI authentication parameters compat_realm and upn_username to control whether NetBIOS or Kerberos realm names and user names are used during SSPI authentication Features

    Add new SSPI authentication parameters compat_realm and upn_username to control whether NetBIOS or Kerberos realm names and user names are used during SSPI authentication (Christian Ullrich)

    Original release occurrence · 9.6.0/changes/054

  • Allow sessions to be terminated automatically if they are in idle-in-transaction state for too long Features

    Allow sessions to be terminated automatically if they are in idle-in-transaction state for too long (Vik Fearing)

    This behavior is controlled by the new configuration parameter idle_in_transaction_session_timeout. It can be useful to prevent forgotten transactions from holding locks or preventing vacuum cleanup for too long.

    Original release occurrence · 9.6.0/changes/055

  • Raise the maximum allowed value of checkpoint_timeout to 24 hours Features

    Raise the maximum allowed value of checkpoint_timeout to 24 hours (Simon Riggs)

    Original release occurrence · 9.6.0/changes/056

  • Allow effective_io_concurrency to be set per-tablespace to support cases where different tablespaces have different I/O characteristics Features

    Allow effective_io_concurrency to be set per-tablespace to support cases where different tablespaces have different I/O characteristics (Julien Rouhaud)

    Original release occurrence · 9.6.0/changes/057

  • Add log_line_prefix option %n to print the current time in Unix epoch form, with milliseconds Features

    Add log_line_prefix option %n to print the current time in Unix epoch form, with milliseconds (Tomas Vondra, Jeff Davis)

    Original release occurrence · 9.6.0/changes/058

  • Add syslog_sequence_numbers and syslog_split_messages configuration parameters to provide more control over the message format when logging to syslog Features

    Add syslog_sequence_numbers and syslog_split_messages configuration parameters to provide more control over the message format when logging to syslog (Peter Eisentraut)

    Original release occurrence · 9.6.0/changes/059

  • Merge the archive and hot_standby values of the wal_level configuration parameter into a single new value replica Features

    Merge the archive and hot_standby values of the wal_level configuration parameter into a single new value replica (Peter Eisentraut)

    Making a distinction between these settings is no longer useful, and merging them is a step towards a planned future simplification of replication setup. The old names are still accepted but are converted to replica internally.

    Original release occurrence · 9.6.0/changes/060

  • Add configure option --with-systemd to enable calling sd_notify() at server start and stop Features

    Add configure option --with-systemd to enable calling sd_notify() at server start and stop (Peter Eisentraut)

    This allows the use of systemd service units of type notify, which greatly simplifies the management of PostgreSQL under systemd.

    Original release occurrence · 9.6.0/changes/061

  • Allow the server's SSL key file to have group read access if it is owned by root Features

    Allow the server's SSL key file to have group read access if it is owned by root (Christoph Berg)

    Formerly, we insisted the key file be owned by the user running the PostgreSQL server, but that is inconvenient on some systems (such as Debian) that are configured to manage certificates centrally. Therefore, allow the case where the key file is owned by root and has group read access. It is up to the operating system administrator to ensure that the group does not include any untrusted users.

    Original release occurrence · 9.6.0/changes/062

  • Force backends to exit if the postmaster dies Features

    Force backends to exit if the postmaster dies (Rajeev Rastogi, Robert Haas)

    Under normal circumstances the postmaster should always outlive its child processes. If for some reason the postmaster dies, force backend sessions to exit with an error. Formerly, existing backends would continue to run until their clients disconnect, but that is unsafe and inefficient. It also prevents a new postmaster from being started until the last old backend has exited. Backends will detect postmaster death when waiting for client I/O, so the exit will not be instantaneous, but it should happen no later than the end of the current query.

    Original release occurrence · 9.6.0/changes/063

  • Check for serializability conflicts before reporting constraint-violation failures Features

    Check for serializability conflicts before reporting constraint-violation failures (Thomas Munro)

    When using serializable transaction isolation, it is desirable that any error due to concurrent transactions should manifest as a serialization failure, thereby cueing the application that a retry might succeed. Unfortunately, this does not reliably happen for duplicate-key failures caused by concurrent insertions. This change ensures that such an error will be reported as a serialization error if the application explicitly checked for the presence of a conflicting key (and did not find it) earlier in the transaction.

    Original release occurrence · 9.6.0/changes/064

  • Ensure that invalidation messages are recorded in WAL even when issued by a transaction that has no XID assigned Features

    Ensure that invalidation messages are recorded in WAL even when issued by a transaction that has no XID assigned (Andres Freund)

    This fixes some corner cases in which transactions on standby servers failed to notice changes, such as new indexes.

    Original release occurrence · 9.6.0/changes/065

  • Prevent multiple processes from trying to clean a GIN index's pending list concurrently Features

    Prevent multiple processes from trying to clean a GIN index's pending list concurrently (Teodor Sigaev, Jeff Janes)

    This had been intentionally allowed, but it causes race conditions that can result in vacuum missing index entries it needs to delete.

    Original release occurrence · 9.6.0/changes/066

  • Allow synchronous replication to support multiple simultaneous synchronous standby servers, not just one Features

    Allow synchronous replication to support multiple simultaneous synchronous standby servers, not just one (Masahiko Sawada, Beena Emerson, Michael Paquier, Fujii Masao, Kyotaro Horiguchi)

    The number of standby servers that must acknowledge a commit before it is considered complete is now configurable as part of the synchronous_standby_names parameter.

    Original release occurrence · 9.6.0/changes/067

  • Add new setting remote_apply for configuration parameter synchronous_commit Features

    Add new setting remote_apply for configuration parameter synchronous_commit (Thomas Munro)

    In this mode, the master waits for the transaction to be applied on the standby server, not just written to disk. That means that you can count on a transaction started on the standby to see all commits previously acknowledged by the master.

    Original release occurrence · 9.6.0/changes/068

  • Add a feature to the replication protocol, and a corresponding option to pg_create_physical_replication_slot(), to allow reserving WAL immediately when creating a replication slot Features

    Add a feature to the replication protocol, and a corresponding option to pg_create_physical_replication_slot(), to allow reserving WAL immediately when creating a replication slot (Gurjeet Singh, Michael Paquier)

    This allows the creation of a replication slot to guarantee that all the WAL needed for a base backup will be available.

    Original release occurrence · 9.6.0/changes/069

  • Add a --slot option to pg_basebackup Features

    Add a --slot option to pg_basebackup (Peter Eisentraut)

    This lets pg_basebackup use a replication slot defined for WAL streaming. After the base backup completes, selecting the same slot for regular streaming replication allows seamless startup of the new standby server.

    Original release occurrence · 9.6.0/changes/070

  • Extend pg_start_backup() and pg_stop_backup() to support non-exclusive backups Features

    Extend pg_start_backup() and pg_stop_backup() to support non-exclusive backups (Magnus Hagander)

    Original release occurrence · 9.6.0/changes/071

  • Allow functions that return sets of tuples to return simple NULLs Features

    Allow functions that return sets of tuples to return simple NULLs (Andrew Gierth, Tom Lane)

    In the context of SELECT FROM function(...), a function that returned a set of composite values was previously not allowed to return a plain NULL value as part of the set. Now that is allowed and interpreted as a row of NULLs. This avoids corner-case errors with, for example, unnesting an array of composite values.

    Original release occurrence · 9.6.0/changes/072

  • Fully support array subscripts and field selections in the target column list of an INSERT with multiple VALUES rows Features

    Fully support array subscripts and field selections in the target column list of an INSERT with multiple VALUES rows (Tom Lane)

    Previously, such cases failed if the same target column was mentioned more than once, e.g., INSERT INTO tab (x[1], x[2]) VALUES (...).

    Original release occurrence · 9.6.0/changes/073

  • When appropriate, postpone evaluation of SELECT output expressions until after an ORDER BY sort Features

    When appropriate, postpone evaluation of SELECT output expressions until after an ORDER BY sort (Konstantin Knizhnik)

    This change ensures that volatile or expensive functions in the output list are executed in the order suggested by ORDER BY, and that they are not evaluated more times than required when there is a LIMIT clause. Previously, these properties held if the ordering was performed by an index scan or pre-merge-join sort, but not if it was performed by a top-level sort.

    Original release occurrence · 9.6.0/changes/074

  • Widen counters recording the number of tuples processed to 64 bits Features

    Widen counters recording the number of tuples processed to 64 bits (Andreas Scherbaum)

    This change allows command tags, e.g., SELECT, to correctly report tuple counts larger than 4 billion. This also applies to PL/pgSQL's GET DIAGNOSTICS ... ROW_COUNT command.

    Original release occurrence · 9.6.0/changes/075

  • Avoid doing encoding conversions by converting through the MULE_INTERNAL encoding Features

    Avoid doing encoding conversions by converting through the MULE_INTERNAL encoding (Tom Lane)

    Previously, many conversions for Cyrillic and Central European single-byte encodings were done by converting to a related MULE_INTERNAL coding scheme and then to the destination encoding. Aside from being inefficient, this meant that when the conversion encountered an untranslatable character, the error message would confusingly complain about failure to convert to or from MULE_INTERNAL, rather than the user-visible encoding.

    Original release occurrence · 9.6.0/changes/076

  • Consider performing joins of foreign tables remotely only when the tables will be accessed under the same role ID Features

    Consider performing joins of foreign tables remotely only when the tables will be accessed under the same role ID (Shigeru Hanada, Ashutosh Bapat, Etsuro Fujita)

    Previously, the foreign join pushdown infrastructure left the question of security entirely up to individual foreign data wrappers, but that made it too easy for an FDW to inadvertently create subtle security holes. So, make it the core code's job to determine which role ID will access each table, and do not attempt join pushdown unless the role is the same for all relevant relations.

    Original release occurrence · 9.6.0/changes/077

  • Allow COPY to copy the output of an INSERT/UPDATE/DELETE ... RETURNING query Features

    Allow COPY to copy the output of an INSERT/UPDATE/DELETE ... RETURNING query (Marko Tiikkaja)

    Previously, an intermediate CTE had to be written to get this result.

    Original release occurrence · 9.6.0/changes/078

  • Introduce ALTER object DEPENDS ON EXTENSION Features

    Introduce ALTER object DEPENDS ON EXTENSION (Abhijit Menon-Sen)

    This command allows a database object to be marked as depending on an extension, so that it will be dropped automatically if the extension is dropped (without needing CASCADE). However, the object is not part of the extension, and thus will be dumped separately by pg_dump.

    Original release occurrence · 9.6.0/changes/079

  • Make ALTER object SET SCHEMA do nothing when the object is already in the requested schema, rather than throwing an error as it historically has for most object types Features

    Make ALTER object SET SCHEMA do nothing when the object is already in the requested schema, rather than throwing an error as it historically has for most object types (Marti Raudsepp)

    Original release occurrence · 9.6.0/changes/080

  • Add options to ALTER OPERATOR to allow changing the selectivity functions associated with an existing operator Features

    Add options to ALTER OPERATOR to allow changing the selectivity functions associated with an existing operator (Yury Zhuravlev)

    Original release occurrence · 9.6.0/changes/081

  • Add an IF NOT EXISTS option to ALTER TABLE ADD COLUMN Features

    Add an IF NOT EXISTS option to ALTER TABLE ADD COLUMN (Fabrízio de Royes Mello)

    Original release occurrence · 9.6.0/changes/082

  • Reduce the lock strength needed by ALTER TABLE when setting fillfactor and autovacuum-related relation options Features

    Reduce the lock strength needed by ALTER TABLE when setting fillfactor and autovacuum-related relation options (Fabrízio de Royes Mello, Simon Riggs)

    Original release occurrence · 9.6.0/changes/083

  • Introduce CREATE ACCESS METHOD to allow extensions to create index access methods Features

    Introduce CREATE ACCESS METHOD to allow extensions to create index access methods (Alexander Korotkov, Petr Jelínek)

    Original release occurrence · 9.6.0/changes/084

  • Add a CASCADE option to CREATE EXTENSION to automatically create any extensions the requested one depends on Features

    Add a CASCADE option to CREATE EXTENSION to automatically create any extensions the requested one depends on (Petr Jelínek)

    Original release occurrence · 9.6.0/changes/085

  • Make CREATE TABLE ... LIKE include an OID column if any source table has one Features

    Make CREATE TABLE ... LIKE include an OID column if any source table has one (Bruce Momjian)

    Original release occurrence · 9.6.0/changes/086

  • If a CHECK constraint is declared NOT VALID in a table creation command, automatically mark it as valid Features

    If a CHECK constraint is declared NOT VALID in a table creation command, automatically mark it as valid (Amit Langote, Amul Sul)

    This is safe because the table has no existing rows. This matches the longstanding behavior of FOREIGN KEY constraints.

    Original release occurrence · 9.6.0/changes/087

  • Fix DROP OPERATOR to clear pg_operator.oprcom and pg_operator.oprnegate links to the dropped operator Bug fixes

    Fix DROP OPERATOR to clear pg_operator.oprcom and pg_operator.oprnegate links to the dropped operator (Roma Sokolov)

    Formerly such links were left as-is, which could pose a problem in the somewhat unlikely event that the dropped operator's OID was reused for another operator.

    Original release occurrence · 9.6.0/changes/088

  • Do not show the same subplan twice in EXPLAIN output Features

    Do not show the same subplan twice in EXPLAIN output (Tom Lane)

    In certain cases, typically involving SubPlan nodes in index conditions, EXPLAIN would print data for the same subplan twice.

    Original release occurrence · 9.6.0/changes/089

  • Disallow creation of indexes on system columns, except for OID columns Features

    Disallow creation of indexes on system columns, except for OID columns (David Rowley)

    Such indexes were never considered supported, and would very possibly misbehave since the system might change the system-column fields of a tuple without updating indexes. However, previously there were no error checks to prevent them from being created.

    Original release occurrence · 9.6.0/changes/090

  • Use the privilege system to manage access to sensitive functions Features

    Use the privilege system to manage access to sensitive functions (Stephen Frost)

    Formerly, many security-sensitive functions contained hard-wired checks that would throw an error if they were called by a non-superuser. This forced the use of superuser roles for some relatively pedestrian tasks. The hard-wired error checks are now gone in favor of making initdb revoke the default public EXECUTE privilege on these functions. This allows installations to choose to grant usage of such functions to trusted roles that do not need all superuser privileges.

    Original release occurrence · 9.6.0/changes/091

  • Create some built-in roles that can be used to grant access to what were previously superuser-only functions Features

    Create some built-in roles that can be used to grant access to what were previously superuser-only functions (Stephen Frost)

    Currently the only such role is pg_signal_backend, but more are expected to be added in future.

    Original release occurrence · 9.6.0/changes/092

  • Improve full-text search to support searching for phrases, that is, lexemes appearing adjacent to each other in a specific order, or with a specified distance between them Features

    Improve full-text search to support searching for phrases, that is, lexemes appearing adjacent to each other in a specific order, or with a specified distance between them (Teodor Sigaev, Oleg Bartunov, Dmitry Ivanov)

    A phrase-search query can be specified in tsquery input using the new operators <-> and <N>. The former means that the lexemes before and after it must appear adjacent to each other in that order. The latter means they must be exactly N lexemes apart.

    Original release occurrence · 9.6.0/changes/093

  • Allow omitting one or both boundaries in an array slice specifier, e.g., array_col[3:] Features

    Allow omitting one or both boundaries in an array slice specifier, e.g., array_col[3:] (Yury Zhuravlev)

    Omitted boundaries are taken as the upper or lower limit of the corresponding array subscript. This allows simpler specification for many common use-cases.

    Original release occurrence · 9.6.0/changes/094

  • Be more careful about out-of-range dates and timestamps Features

    Be more careful about out-of-range dates and timestamps (Vitaly Burovoy)

    This change prevents unexpected out-of-range errors for timestamp with time zone values very close to the implementation limits. Previously, the "same" value might be accepted or not depending on the timezone setting, meaning that a dump and reload could fail on a value that had been accepted when presented. Now the limits are enforced according to the equivalent UTC time, not local time, so as to be independent of timezone.

    Also, PostgreSQL is now more careful to detect overflow in operations that compute new date or timestamp values, such as date + integer.

    Original release occurrence · 9.6.0/changes/095

  • For geometric data types, make sure infinity and NaN component values are treated consistently during input and output Features

    For geometric data types, make sure infinity and NaN component values are treated consistently during input and output (Tom Lane)

    Such values will now always print the same as they would in a simple float8 column, and be accepted the same way on input. Previously the behavior was platform-dependent.

    Original release occurrence · 9.6.0/changes/096

  • Upgrade the ispell dictionary type to handle modern Hunspell files and support more languages Features

    Upgrade the ispell dictionary type to handle modern Hunspell files and support more languages (Artur Zakirov)

    Original release occurrence · 9.6.0/changes/097

  • Implement look-behind constraints in regular expressions Features

    Implement look-behind constraints in regular expressions (Tom Lane)

    A look-behind constraint is like a lookahead constraint in that it consumes no text; but it checks for existence (or nonexistence) of a match ending at the current point in the string, rather than one starting at the current point. Similar features exist in many other regular-expression engines.

    Original release occurrence · 9.6.0/changes/098

  • In regular expressions, if an apparent three-digit octal escape \nnn would exceed 377 (255 decimal), assume it is a two-digit octal escape instead Features

    In regular expressions, if an apparent three-digit octal escape \nnn would exceed 377 (255 decimal), assume it is a two-digit octal escape instead (Tom Lane)

    This makes the behavior match current Tcl releases.

    Original release occurrence · 9.6.0/changes/099

  • Add transaction ID operators xid <> xid and xid <> int4, for consistency with the corresponding equality operators Features

    Add transaction ID operators xid <> xid and xid <> int4, for consistency with the corresponding equality operators (Michael Paquier)

    Original release occurrence · 9.6.0/changes/100

  • Add jsonb_insert() function to insert a new element into a jsonb array, or a not-previously-existing key into a jsonb object Features

    Add jsonb_insert() function to insert a new element into a jsonb array, or a not-previously-existing key into a jsonb object (Dmitry Dolgov)

    Original release occurrence · 9.6.0/changes/101

  • Improve the accuracy of the ln(), log(), exp(), and pow() functions for type numeric Features

    Improve the accuracy of the ln(), log(), exp(), and pow() functions for type numeric (Dean Rasheed)

    Original release occurrence · 9.6.0/changes/102

  • Add a scale(numeric) function to extract the display scale of a numeric value Features

    Add a scale(numeric) function to extract the display scale of a numeric value (Marko Tiikkaja)

    Original release occurrence · 9.6.0/changes/103

  • Add trigonometric functions that work in degrees Features

    Add trigonometric functions that work in degrees (Dean Rasheed)

    For example, sind() measures its argument in degrees, whereas sin() measures in radians. These functions go to some lengths to deliver exact results for values where an exact result can be expected, for instance sind(30) = 0.5.

    Original release occurrence · 9.6.0/changes/104

  • Ensure that trigonometric functions handle infinity and NaN inputs per the POSIX standard Features

    Ensure that trigonometric functions handle infinity and NaN inputs per the POSIX standard (Dean Rasheed)

    The POSIX standard says that these functions should return NaN for NaN input, and should throw an error for out-of-range inputs including infinity. Previously our behavior varied across platforms.

    Original release occurrence · 9.6.0/changes/105

  • Make to_timestamp(float8) convert float infinity to timestamp infinity Features

    Make to_timestamp(float8) convert float infinity to timestamp infinity (Vitaly Burovoy)

    Formerly it just failed on an infinite input.

    Original release occurrence · 9.6.0/changes/106

  • Add new functions for tsvector data Features

    Add new functions for tsvector data (Stas Kelvich)

    The new functions are ts_delete(), ts_filter(), unnest(), tsvector_to_array(), array_to_tsvector(), and a variant of setweight() that sets the weight only for specified lexeme(s).

    Original release occurrence · 9.6.0/changes/107

  • Allow ts_stat() and tsvector_update_trigger() to operate on values that are of types binary-compatible with the expected argument type, not just exactly that type; for example allow citext where text is expected Features

    Allow ts_stat() and tsvector_update_trigger() to operate on values that are of types binary-compatible with the expected argument type, not just exactly that type; for example allow citext where text is expected (Teodor Sigaev)

    Original release occurrence · 9.6.0/changes/108

  • Add variadic functions num_nulls() and num_nonnulls() that count the number of their arguments that are null or non-null Features

    Add variadic functions num_nulls() and num_nonnulls() that count the number of their arguments that are null or non-null (Marko Tiikkaja)

    An example usage is CHECK(num_nonnulls(a,b,c) = 1) which asserts that exactly one of a,b,c is not NULL. These functions can also be used to count the number of null or nonnull elements in an array.

    Original release occurrence · 9.6.0/changes/109

  • Add function parse_ident() to split a qualified, possibly quoted SQL identifier into its parts Features

    Add function parse_ident() to split a qualified, possibly quoted SQL identifier into its parts (Pavel Stehule)

    Original release occurrence · 9.6.0/changes/110

  • In to_number(), interpret a V format code as dividing by 10 to the power of the number of digits following V Features

    In to_number(), interpret a V format code as dividing by 10 to the power of the number of digits following V (Bruce Momjian)

    This makes it operate in an inverse fashion to to_char().

    Original release occurrence · 9.6.0/changes/111

  • Make the to_reg*() functions accept type text not cstring Features

    Make the to_reg*() functions accept type text not cstring (Petr Korobeinikov)

    This avoids the need to write an explicit cast in most cases where the argument is not a simple literal constant.

    Original release occurrence · 9.6.0/changes/112

  • Add pg_size_bytes() function to convert human-readable size strings to numbers Features

    Add pg_size_bytes() function to convert human-readable size strings to numbers (Pavel Stehule, Vitaly Burovoy, Dean Rasheed)

    This function converts strings like those produced by pg_size_pretty() into bytes. An example usage is SELECT oid::regclass FROM pg_class WHERE pg_total_relation_size(oid) > pg_size_bytes('10 GB').

    Original release occurrence · 9.6.0/changes/113

  • In pg_size_pretty(), format negative numbers similarly to positive ones Features

    In pg_size_pretty(), format negative numbers similarly to positive ones (Adrian Vondendriesch)

    Previously, negative numbers were never abbreviated, just printed in bytes.

    Original release occurrence · 9.6.0/changes/114

  • Add an optional missing_ok argument to the current_setting() function Features

    Add an optional missing_ok argument to the current_setting() function (David Christensen)

    This allows avoiding an error for an unrecognized parameter name, instead returning a NULL.

    Original release occurrence · 9.6.0/changes/115

  • Change various catalog-inspection functions to return NULL for invalid input Features

    Change various catalog-inspection functions to return NULL for invalid input (Michael Paquier)

    pg_get_viewdef() now returns NULL if given an invalid view OID, and several similar functions likewise return NULL for bad input. Previously, such cases usually led to "cache lookup failed" errors, which are not meant to occur in user-facing cases.

    Original release occurrence · 9.6.0/changes/116

  • Fix pg_replication_origin_xact_reset() to not have any arguments Bug fixes

    Fix pg_replication_origin_xact_reset() to not have any arguments (Fujii Masao)

    The documentation said that it has no arguments, and the C code did not expect any arguments, but the entry in pg_proc mistakenly specified two arguments.

    Original release occurrence · 9.6.0/changes/117

  • In PL/pgSQL, detect mismatched CONTINUE and EXIT statements while compiling a function, rather than at execution time Features

    In PL/pgSQL, detect mismatched CONTINUE and EXIT statements while compiling a function, rather than at execution time (Jim Nasby)

    Original release occurrence · 9.6.0/changes/118

  • Extend PL/Python's error-reporting and message-reporting functions to allow specifying additional message fields besides the primary error message Features

    Extend PL/Python's error-reporting and message-reporting functions to allow specifying additional message fields besides the primary error message (Pavel Stehule)

    Original release occurrence · 9.6.0/changes/119

  • Allow PL/Python functions to call themselves recursively via SPI, and fix the behavior when multiple set-returning PL/Python functions are called within one query Bug fixes

    Allow PL/Python functions to call themselves recursively via SPI, and fix the behavior when multiple set-returning PL/Python functions are called within one query (Alexey Grishchenko, Tom Lane)

    Original release occurrence · 9.6.0/changes/120

  • Fix session-lifespan memory leaks in PL/Python Bug fixes

    Fix session-lifespan memory leaks in PL/Python (Heikki Linnakangas, Haribabu Kommi, Tom Lane)

    Original release occurrence · 9.6.0/changes/121

  • Modernize PL/Tcl to use Tcl's "object" APIs instead of simple strings Features

    Modernize PL/Tcl to use Tcl's "object" APIs instead of simple strings (Jim Nasby, Karl Lehenbauer)

    This can improve performance substantially in some cases. Note that PL/Tcl now requires Tcl 8.4 or later.

    Original release occurrence · 9.6.0/changes/122

  • In PL/Tcl, make database-reported errors return additional information in Tcl's errorCode global variable Features

    In PL/Tcl, make database-reported errors return additional information in Tcl's errorCode global variable (Jim Nasby, Tom Lane)

    This feature follows the Tcl convention for returning auxiliary data about an error.

    Original release occurrence · 9.6.0/changes/123

  • Fix PL/Tcl to perform encoding conversion between the database encoding and UTF-8, which is what Tcl expects Bug fixes

    Fix PL/Tcl to perform encoding conversion between the database encoding and UTF-8, which is what Tcl expects (Tom Lane)

    Previously, strings were passed through without conversion, leading to misbehavior with non-ASCII characters when the database encoding was not UTF-8.

    Original release occurrence · 9.6.0/changes/124

  • Add a nonlocalized version of the severity field in error and notice messages Features

    Add a nonlocalized version of the severity field in error and notice messages (Tom Lane)

    This change allows client code to determine severity of an error or notice without having to worry about localized variants of the severity strings.

    Original release occurrence · 9.6.0/changes/125

  • Introduce a feature in libpq whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages Features

    Introduce a feature in libpq whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages (Pavel Stehule)

    The default behavior of PQerrorMessage() is now to print CONTEXT only for errors. The new function PQsetErrorContextVisibility() can be used to adjust this.

    Original release occurrence · 9.6.0/changes/126

  • Add support in libpq for regenerating an error message with a different verbosity level Features

    Add support in libpq for regenerating an error message with a different verbosity level (Alex Shulgin)

    This is done with the new function PQresultVerboseErrorMessage(). This supports psql's new \errverbose feature, and may be useful for other clients as well.

    Original release occurrence · 9.6.0/changes/127

  • Improve libpq's PQhost() function to return useful data for default Unix-socket connections Features

    Improve libpq's PQhost() function to return useful data for default Unix-socket connections (Tom Lane)

    Previously it would return NULL if no explicit host specification had been given; now it returns the default socket directory path.

    Original release occurrence · 9.6.0/changes/128

  • Fix ecpg's lexer to handle line breaks within comments starting on preprocessor directive lines Bug fixes

    Fix ecpg's lexer to handle line breaks within comments starting on preprocessor directive lines (Michael Meskes)

    Original release occurrence · 9.6.0/changes/129

  • Add a --strict-names option to pg_dump and pg_restore Features

    Add a --strict-names option to pg_dump and pg_restore (Pavel Stehule)

    This option causes the program to complain if there is no match for a -t or -n option, rather than silently doing nothing.

    Original release occurrence · 9.6.0/changes/130

  • In pg_dump, dump locally-made changes of privilege assignments for system objects Features

    In pg_dump, dump locally-made changes of privilege assignments for system objects (Stephen Frost)

    While it has always been possible for a superuser to change the privilege assignments for built-in or extension-created objects, such changes were formerly lost in a dump and reload. Now, pg_dump recognizes and dumps such changes. (This works only when dumping from a 9.6 or later server, however.)

    Original release occurrence · 9.6.0/changes/131

  • Allow pg_dump to dump non-extension-owned objects that are within an extension-owned schema Features

    Allow pg_dump to dump non-extension-owned objects that are within an extension-owned schema (Martín Marqués)

    Previously such objects were ignored because they were mistakenly assumed to belong to the extension owning their schema.

    Original release occurrence · 9.6.0/changes/132

  • In pg_dump output, include the table name in object tags for object types that are only uniquely named per-table (for example, triggers) Features

    In pg_dump output, include the table name in object tags for object types that are only uniquely named per-table (for example, triggers) (Peter Eisentraut)

    Original release occurrence · 9.6.0/changes/133

  • Support multiple -c and -f command-line options Features

    Support multiple -c and -f command-line options (Pavel Stehule, Catalin Iacob)

    The specified operations are carried out in the order in which the options are given, and then psql terminates.

    Original release occurrence · 9.6.0/changes/134

  • Add a \crosstabview command that prints the results of a query in a cross-tabulated display Features

    Add a \crosstabview command that prints the results of a query in a cross-tabulated display (Daniel Vérité)

    In the crosstab display, data values from one query result column are placed in a grid whose column and row headers come from other query result columns.

    Original release occurrence · 9.6.0/changes/135

  • Add an \errverbose command that shows the last server error at full verbosity Features

    Add an \errverbose command that shows the last server error at full verbosity (Alex Shulgin)

    This is useful after getting an unexpected error — you no longer need to adjust the VERBOSITY variable and recreate the failure in order to see error fields that are not shown by default.

    Original release occurrence · 9.6.0/changes/136

  • Add \ev and \sv commands for editing and showing view definitions Features

    Add \ev and \sv commands for editing and showing view definitions (Petr Korobeinikov)

    These are parallel to the existing \ef and \sf commands for functions.

    Original release occurrence · 9.6.0/changes/137

  • Add a \gexec command that executes a query and re-submits the result(s) as new queries Features

    Add a \gexec command that executes a query and re-submits the result(s) as new queries (Corey Huinker)

    Original release occurrence · 9.6.0/changes/138

  • Allow \pset C string to set the table title, for consistency with \C string Features

    Allow \pset C string to set the table title, for consistency with \C string (Bruce Momjian)

    Original release occurrence · 9.6.0/changes/139

  • In \pset expanded auto mode, do not use expanded format for query results with only one column Features

    In \pset expanded auto mode, do not use expanded format for query results with only one column (Andreas Karlsson, Robert Haas)

    Original release occurrence · 9.6.0/changes/140

  • Improve the headers output by the \watch command Features

    Improve the headers output by the \watch command (Michael Paquier, Tom Lane)

    Include the \pset title string if one has been set, and shorten the prefabricated part of the header to be timestamp (every Ns). Also, the timestamp format now obeys psql's locale environment.

    Original release occurrence · 9.6.0/changes/141

  • Improve tab-completion logic to consider the entire input query, not only the current line Features

    Improve tab-completion logic to consider the entire input query, not only the current line (Tom Lane)

    Previously, breaking a command into multiple lines defeated any tab completion rules that needed to see words on earlier lines.

    Original release occurrence · 9.6.0/changes/142

  • Numerous minor improvements in tab-completion behavior Features

    Numerous minor improvements in tab-completion behavior (Peter Eisentraut, Vik Fearing, Kevin Grittner, Kyotaro Horiguchi, Jeff Janes, Andreas Karlsson, Fujii Masao, Thomas Munro, Masahiko Sawada, Pavel Stehule)

    Original release occurrence · 9.6.0/changes/143

  • Add a PROMPT option %p to insert the process ID of the connected backend Features

    Add a PROMPT option %p to insert the process ID of the connected backend (Julien Rouhaud)

    Original release occurrence · 9.6.0/changes/144

  • Introduce a feature whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages Features

    Introduce a feature whereby the CONTEXT field of messages can be suppressed, either always or only for non-error messages (Pavel Stehule)

    Printing CONTEXT only for errors is now the default behavior. This can be changed by setting the special variable SHOW_CONTEXT.

    Original release occurrence · 9.6.0/changes/145

  • Make \df+ show function access privileges and parallel-safety attributes Features

    Make \df+ show function access privileges and parallel-safety attributes (Michael Paquier)

    Original release occurrence · 9.6.0/changes/146

  • SQL commands in pgbench scripts are now ended by semicolons, not newlines Features

    SQL commands in pgbench scripts are now ended by semicolons, not newlines (Kyotaro Horiguchi, Tom Lane)

    This change allows SQL commands in scripts to span multiple lines. Existing custom scripts will need to be modified to add a semicolon at the end of each line that does not have one already. (Doing so does not break the script for use with older versions of pgbench.)

    Original release occurrence · 9.6.0/changes/147

  • Support floating-point arithmetic, as well as some built-in functions, in expressions in backslash commands Features

    Support floating-point arithmetic, as well as some built-in functions, in expressions in backslash commands (Fabien Coelho)

    Original release occurrence · 9.6.0/changes/148

  • Replace \setrandom with built-in functions Features

    Replace \setrandom with built-in functions (Fabien Coelho)

    The new built-in functions include random(), random_exponential(), and random_gaussian(), which perform the same work as \setrandom, but are easier to use since they can be embedded in larger expressions. Since these additions have made \setrandom obsolete, remove it.

    Original release occurrence · 9.6.0/changes/149

  • Allow invocation of multiple copies of the built-in scripts, not only custom scripts Features

    Allow invocation of multiple copies of the built-in scripts, not only custom scripts (Fabien Coelho)

    This is done with the new -b switch, which works similarly to -f for custom scripts.

    Original release occurrence · 9.6.0/changes/150

  • Allow changing the selection probabilities (weights) for scripts Features

    Allow changing the selection probabilities (weights) for scripts (Fabien Coelho)

    When multiple scripts are specified, each pgbench transaction randomly chooses one to execute. Formerly this was always done with uniform probability, but now different selection probabilities can be specified for different scripts.

    Original release occurrence · 9.6.0/changes/151

  • Collect statistics for each script in a multi-script run Features

    Collect statistics for each script in a multi-script run (Fabien Coelho)

    This feature adds an intermediate level of detail to existing global and per-command statistics printouts.

    Original release occurrence · 9.6.0/changes/152

  • Add a --progress-timestamp option to report progress with Unix epoch timestamps, instead of time since the run started Features

    Add a --progress-timestamp option to report progress with Unix epoch timestamps, instead of time since the run started (Fabien Coelho)

    Original release occurrence · 9.6.0/changes/153

  • Allow the number of client connections (-c) to not be an exact multiple of the number of threads (-j) Features

    Allow the number of client connections (-c) to not be an exact multiple of the number of threads (-j) (Fabien Coelho)

    Original release occurrence · 9.6.0/changes/154

  • When the -T option is used, stop promptly at the end of the specified time Features

    When the -T option is used, stop promptly at the end of the specified time (Fabien Coelho)

    Previously, specifying a low transaction rate could cause pgbench to wait significantly longer than specified.

    Original release occurrence · 9.6.0/changes/155

  • Improve error reporting during initdb's post-bootstrap phase Features

    Improve error reporting during initdb's post-bootstrap phase (Tom Lane)

    Previously, an error here led to reporting the entire input file as the "failing query"; now just the current query is reported. To get the desired behavior, queries in initdb's input files must be separated by blank lines.

    Original release occurrence · 9.6.0/changes/156

  • Speed up initdb by using just one standalone-backend session for all the post-bootstrap steps Performance

    Speed up initdb by using just one standalone-backend session for all the post-bootstrap steps (Tom Lane)

    Original release occurrence · 9.6.0/changes/157

  • Improve pg_rewind so that it can work when the target timeline changes Features

    Improve pg_rewind so that it can work when the target timeline changes (Alexander Korotkov)

    This allows, for example, rewinding a promoted standby back to some state of the old master's timeline.

    Original release occurrence · 9.6.0/changes/158

  • Remove obsolete heap_formtuple/heap_modifytuple/heap_deformtuple functions Features

    Remove obsolete heap_formtuple/heap_modifytuple/heap_deformtuple functions (Peter Geoghegan)

    Original release occurrence · 9.6.0/changes/159

  • Add macros to make AllocSetContextCreate() calls simpler and safer Features

    Add macros to make AllocSetContextCreate() calls simpler and safer (Tom Lane)

    Writing out the individual sizing parameters for a memory context is now deprecated in favor of using one of the new macros ALLOCSET_DEFAULT_SIZES, ALLOCSET_SMALL_SIZES, or ALLOCSET_START_SMALL_SIZES. Existing code continues to work, however.

    Original release occurrence · 9.6.0/changes/160

  • Unconditionally use static inline functions in header files Features

    Unconditionally use static inline functions in header files (Andres Freund)

    This may result in warnings and/or wasted code space with very old compilers, but the notational improvement seems worth it.

    Original release occurrence · 9.6.0/changes/161

  • Improve TAP testing infrastructure Features

    Improve TAP testing infrastructure (Michael Paquier, Craig Ringer, Álvaro Herrera, Stephen Frost)

    Notably, it is now possible to test recovery scenarios using this infrastructure.

    Original release occurrence · 9.6.0/changes/162

  • Make trace_lwlocks identify individual locks by name Features

    Make trace_lwlocks identify individual locks by name (Robert Haas)

    Original release occurrence · 9.6.0/changes/163

  • Improve psql's tab-completion code infrastructure Features

    Improve psql's tab-completion code infrastructure (Thomas Munro, Michael Paquier)

    Tab-completion rules are now considerably easier to write, and more compact.

    Original release occurrence · 9.6.0/changes/164

  • Nail the pg_shseclabel system catalog into cache, so that it is available for access during connection authentication Features

    Nail the pg_shseclabel system catalog into cache, so that it is available for access during connection authentication (Adam Brightwell)

    The core code does not use this catalog for authentication, but extensions might wish to consult it.

    Original release occurrence · 9.6.0/changes/165

  • Restructure index access method API to hide most of it at the C level Features

    Restructure index access method API to hide most of it at the C level (Alexander Korotkov, Andrew Gierth)

    This change modernizes the index AM API to look more like the designs we have adopted for foreign data wrappers and tablesample handlers. This simplifies the C code and makes it much more practical to define index access methods in installable extensions. A consequence is that most of the columns of the pg_am system catalog have disappeared. New inspection functions have been added to allow SQL queries to determine index AM properties that used to be discoverable from pg_am.

    Original release occurrence · 9.6.0/changes/166

  • Add pg_init_privs system catalog to hold original privileges of initdb-created and extension-created objects Features

    Add pg_init_privs system catalog to hold original privileges of initdb-created and extension-created objects (Stephen Frost)

    This infrastructure allows pg_dump to dump changes that an installation may have made in privileges attached to system objects. Formerly, such changes would be lost in a dump and reload, but now they are preserved.

    Original release occurrence · 9.6.0/changes/167

  • Change the way that extensions allocate custom LWLocks Features

    Change the way that extensions allocate custom LWLocks (Amit Kapila, Robert Haas)

    The RequestAddinLWLocks() function is removed, and replaced by RequestNamedLWLockTranche(). This allows better identification of custom LWLocks, and is less error-prone.

    Original release occurrence · 9.6.0/changes/168

  • Improve the isolation tester to allow multiple sessions to wait concurrently, allowing testing of deadlock scenarios Features

    Improve the isolation tester to allow multiple sessions to wait concurrently, allowing testing of deadlock scenarios (Robert Haas)

    Original release occurrence · 9.6.0/changes/169

  • Introduce extensible node types Features

    Introduce extensible node types (KaiGai Kohei)

    This change allows FDWs or custom scan providers to store data in a plan tree in a more convenient format than was previously possible.

    Original release occurrence · 9.6.0/changes/170

  • Make the planner deal with post-scan/join query steps by generating and comparing Paths, replacing a lot of ad-hoc logic Features

    Make the planner deal with post-scan/join query steps by generating and comparing Paths, replacing a lot of ad-hoc logic (Tom Lane)

    This change provides only marginal user-visible improvements today, but it enables future work on a lot of upper-planner improvements that were impractical to tackle using the old code structure.

    Original release occurrence · 9.6.0/changes/171

  • Support partial aggregation Features

    Support partial aggregation (David Rowley, Simon Riggs)

    This change allows the computation of an aggregate function to be split into separate parts, for example so that parallel worker processes can cooperate on computing an aggregate. In future it might allow aggregation across local and remote data to occur partially on the remote end.

    Original release occurrence · 9.6.0/changes/172

  • Add a generic command progress reporting facility Features

    Add a generic command progress reporting facility (Vinayak Pokale, Rahila Syed, Amit Langote, Robert Haas)

    Original release occurrence · 9.6.0/changes/173

  • Separate out psql's flex lexer to make it usable by other client programs Features

    Separate out psql's flex lexer to make it usable by other client programs (Tom Lane, Kyotaro Horiguchi)

    This eliminates code duplication for programs that need to be able to parse SQL commands well enough to identify command boundaries. Doing that in full generality is more painful than one could wish, and up to now only psql has really gotten it right among our supported client programs.

    A new source-code subdirectory src/fe_utils/ has been created to hold this and other code that is shared across our client programs. Formerly such sharing was accomplished by symbolic linking or copying source files at build time, which was ugly and required duplicate compilation.

    Original release occurrence · 9.6.0/changes/174

  • Introduce WaitEventSet API to allow efficient waiting for event sets that usually do not change from one wait to the next Features

    Introduce WaitEventSet API to allow efficient waiting for event sets that usually do not change from one wait to the next (Andres Freund, Amit Kapila)

    Original release occurrence · 9.6.0/changes/175

  • Add a generic interface for writing WAL records Features

    Add a generic interface for writing WAL records (Alexander Korotkov, Petr Jelínek, Markus Nullmeier)

    This change allows extensions to write WAL records for changes to pages using a standard layout. The problem of needing to replay WAL without access to the extension is solved by having generic replay code. This allows extensions to implement, for example, index access methods and have WAL support for them.

    Original release occurrence · 9.6.0/changes/176

  • Support generic WAL messages for logical decoding Features

    Support generic WAL messages for logical decoding (Petr Jelínek, Andres Freund)

    This feature allows extensions to insert data into the WAL stream that can be read by logical-decoding plugins, but is not connected to physical data restoration.

    Original release occurrence · 9.6.0/changes/177

  • Allow SP-GiST operator classes to store an arbitrary "traversal value" while descending the index Features

    Allow SP-GiST operator classes to store an arbitrary "traversal value" while descending the index (Alexander Lebedev, Teodor Sigaev)

    This is somewhat like the "reconstructed value", but it could be any arbitrary chunk of data, not necessarily of the same data type as the indexed column.

    Original release occurrence · 9.6.0/changes/178

  • Introduce a LOG_SERVER_ONLY message level for ereport() Features

    Introduce a LOG_SERVER_ONLY message level for ereport() (David Steele)

    This level acts like LOG except that the message is never sent to the client. It is meant for use in auditing and similar applications.

    Original release occurrence · 9.6.0/changes/179

  • Provide a Makefile target to build all generated headers Features

    Provide a Makefile target to build all generated headers (Michael Paquier, Tom Lane)

    submake-generated-headers can now be invoked to ensure that generated backend header files are up-to-date. This is useful in subdirectories that might be built "standalone".

    Original release occurrence · 9.6.0/changes/180

  • Support OpenSSL 1.1.0 Features

    Support OpenSSL 1.1.0 (Andreas Karlsson, Heikki Linnakangas)

    Original release occurrence · 9.6.0/changes/181

  • Add configuration parameter auto_explain.sample_rate to allow contrib/auto_explain to capture just a configurable fraction of all queries Features

    Add configuration parameter auto_explain.sample_rate to allow contrib/auto_explain to capture just a configurable fraction of all queries (Craig Ringer, Julien Rouhaud)

    This allows reduction of overhead for heavy query traffic, while still getting useful information on average.

    Original release occurrence · 9.6.0/changes/182

  • Add contrib/bloom module that implements an index access method based on Bloom filtering Features

    Add contrib/bloom module that implements an index access method based on Bloom filtering (Teodor Sigaev, Alexander Korotkov)

    This is primarily a proof-of-concept for non-core index access methods, but it could be useful in its own right for queries that search many columns.

    Original release occurrence · 9.6.0/changes/183

  • In contrib/cube, introduce distance operators for cubes, and support kNN-style searches in GiST indexes on cube columns Features

    In contrib/cube, introduce distance operators for cubes, and support kNN-style searches in GiST indexes on cube columns (Stas Kelvich)

    Original release occurrence · 9.6.0/changes/184

  • Make contrib/hstore's hstore_to_jsonb_loose() and hstore_to_json_loose() functions agree on what is a number Features

    Make contrib/hstore's hstore_to_jsonb_loose() and hstore_to_json_loose() functions agree on what is a number (Tom Lane)

    Previously, hstore_to_jsonb_loose() would convert numeric-looking strings to JSON numbers, rather than strings, even if they did not exactly match the JSON syntax specification for numbers. This was inconsistent with hstore_to_json_loose(), so tighten the test to match the JSON syntax.

    Original release occurrence · 9.6.0/changes/185

  • Add selectivity estimation functions for contrib/intarray operators to improve plans for queries using those operators Features

    Add selectivity estimation functions for contrib/intarray operators to improve plans for queries using those operators (Yury Zhuravlev, Alexander Korotkov)

    Original release occurrence · 9.6.0/changes/186

  • Make contrib/pageinspect's heap_page_items() function show the raw data in each tuple, and add new functions tuple_data_split() and heap_page_item_attrs() for inspection of individual tuple fields Features

    Make contrib/pageinspect's heap_page_items() function show the raw data in each tuple, and add new functions tuple_data_split() and heap_page_item_attrs() for inspection of individual tuple fields (Nikolay Shaplov)

    Original release occurrence · 9.6.0/changes/187

  • Add an optional S2K iteration count parameter to contrib/pgcrypto's pgp_sym_encrypt() function Features

    Add an optional S2K iteration count parameter to contrib/pgcrypto's pgp_sym_encrypt() function (Jeff Janes)

    Original release occurrence · 9.6.0/changes/188

  • Add support for "word similarity" to contrib/pg_trgm Features

    Add support for "word similarity" to contrib/pg_trgm (Alexander Korotkov, Artur Zakirov)

    These functions and operators measure the similarity between one string and the most similar single word of another string.

    Original release occurrence · 9.6.0/changes/189

  • Add configuration parameter pg_trgm.similarity_threshold for contrib/pg_trgm's similarity threshold Features

    Add configuration parameter pg_trgm.similarity_threshold for contrib/pg_trgm's similarity threshold (Artur Zakirov)

    This threshold has always been configurable, but formerly it was controlled by special-purpose functions set_limit() and show_limit(). Those are now deprecated.

    Original release occurrence · 9.6.0/changes/190

  • Improve contrib/pg_trgm's GIN operator class to speed up index searches in which both common and rare keys appear Performance

    Improve contrib/pg_trgm's GIN operator class to speed up index searches in which both common and rare keys appear (Jeff Janes)

    Original release occurrence · 9.6.0/changes/191

  • Improve performance of similarity searches in contrib/pg_trgm GIN indexes Performance

    Improve performance of similarity searches in contrib/pg_trgm GIN indexes (Christophe Fornaroli)

    Original release occurrence · 9.6.0/changes/192

  • Add contrib/pg_visibility module to allow examining table visibility maps Features

    Add contrib/pg_visibility module to allow examining table visibility maps (Robert Haas)

    Original release occurrence · 9.6.0/changes/193

  • Add ssl_extension_info() function to contrib/sslinfo, to print information about SSL extensions present in the X509 certificate used for the current connection Features

    Add ssl_extension_info() function to contrib/sslinfo, to print information about SSL extensions present in the X509 certificate used for the current connection (Dmitry Voronin)

    Original release occurrence · 9.6.0/changes/194

  • Allow extension-provided operators and functions to be sent for remote execution, if the extension is whitelisted in the foreign server's options Features

    Allow extension-provided operators and functions to be sent for remote execution, if the extension is whitelisted in the foreign server's options (Paul Ramsey)

    Users can enable this feature when the extension is known to exist in a compatible version in the remote database. It allows more efficient execution of queries involving extension operators.

    Original release occurrence · 9.6.0/changes/195

  • Consider performing sorts on the remote server Features

    Consider performing sorts on the remote server (Ashutosh Bapat)

    Original release occurrence · 9.6.0/changes/196

  • Consider performing joins on the remote server Features

    Consider performing joins on the remote server (Shigeru Hanada, Ashutosh Bapat)

    Original release occurrence · 9.6.0/changes/197

  • When feasible, perform UPDATE or DELETE entirely on the remote server Features

    When feasible, perform UPDATE or DELETE entirely on the remote server (Etsuro Fujita)

    Formerly, remote updates involved sending a SELECT FOR UPDATE command and then updating or deleting the selected rows one-by-one. While that is still necessary if the operation requires any local processing, it can now be done remotely if all elements of the query are safe to send to the remote server.

    Original release occurrence · 9.6.0/changes/198

  • Allow the fetch size to be set as a server or table option Features

    Allow the fetch size to be set as a server or table option (Corey Huinker)

    Formerly, postgres_fdw always fetched 100 rows at a time from remote queries; now that behavior is configurable.

    Original release occurrence · 9.6.0/changes/199

  • Use a single foreign-server connection for local user IDs that all map to the same remote user Features

    Use a single foreign-server connection for local user IDs that all map to the same remote user (Ashutosh Bapat)

    Original release occurrence · 9.6.0/changes/200

  • Transmit query cancellation requests to the remote server Features

    Transmit query cancellation requests to the remote server (Michael Paquier, Etsuro Fujita)

    Previously, a local query cancellation request did not cause an already-sent remote query to terminate early.

    Original release occurrence · 9.6.0/changes/201

Security evidence

34 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2021-3449 · CVE-2021-3449

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 9.6.22. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 9.6.22. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Release-note mentions:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 9.6.24. Component: client.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 9.6.24. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

Fixed in this branch: 9.6.20. Component: client.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

Fixed in this branch: 9.6.20. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

Fixed in this branch: 9.6.20. Component: client.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-1720 · ALTER ... DEPENDS ON EXTENSION is missing authorization checks. CVSS 3.1

The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE , or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION . The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 9.6.17. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2020-14350 · Uncontrolled search path element in CREATE EXTENSION CVSS 7.1

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable. In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 9.6.19. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-10733 · Windows installer runs executables from uncontrolled directories CVSS 6.7

The Windows installer for PostgreSQL invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. The PostgreSQL project thanks Hou JingYi (@hjy79425575) for reporting this problem.

Fixed in this branch: 9.6.18. Component: packaging.

Official affected-branch entry: 9.6.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-3466 · pg_ctlcluster script in postgresql-common does not drop privileges when creating socket/statistics temporary directories CVSS 8.4

A PostgreSQL superuser could escalate to root using a deficiency in the pg_ctlcluster command. pg_ctlcluster is a utility provided by the "postgresql-common" package that is installed with PostgreSQL on Debian and Ubuntu platforms.

Fixed in this branch: 9.6.16. Component: packaging.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVE-2019-10211 · Windows installer bundled OpenSSL executes code from unprotected directory CVSS 7.8

When the database server or libpq client library initializes SSL, libeay32.dll attempts to read configuration from a hard-coded directory. Typically, the directory does not exist, but any local user could create it and inject configuration. This configuration can direct OpenSSL to load and execute arbitrary code as the user running a PostgreSQL server or client. Most PostgreSQL client tools and libraries use libpq , and one can encounter this vulnerability by using any of them. This vulnerability is much like CVE-2019-5443 , but it originated independently. One can work around the vulnerability by setting environment variable OPENSSL_CONF to "NUL:/openssl.cnf" or any other name that cannot exist as a file. The PostgreSQL project thanks Daniel Gustafsson of the curl security team for reporting this problem.

Fixed in this branch: 9.6.15. Component: packaging.

Official affected-branch entry: 9.6.

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10210 · Windows installer writes superuser password to unprotected temporary file CVSS 6.7

The EnterpriseDB Windows installer writes a password to a temporary file in its installation directory, creates initial databases, and deletes the file. During those seconds while the file exists, a local attacker can read the PostgreSQL superuser password from the file. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 9.6.15. Component: packaging.

Official affected-branch entry: 9.6.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10208 · TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution CVSS 7.5

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 9.6.15. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2019-10130 · Selectivity estimators bypass row security policies CVSS 3.1

PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user able to execute SQL queries with permissions to read a given column could craft a leaky operator that could read whatever data had been sampled from that column. If this happened to include values from rows that the user is forbidden to see by a row security policy, the user could effectively bypass the policy. This is fixed by only allowing a non-leakproof operator to use this data if there are no relevant row security policies for the table. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

Fixed in this branch: 9.6.13. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2019-10128 · EnterpriseDB Windows installer does not clear permissive ACL entries CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

Fixed in this branch: 9.6.13. Component: packaging.

Official affected-branch entry: 9.6.

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2019-10127 · BigSQL Windows installer does not clear permissive ACL entries. CVSS 7.0

Due to both the EnterpriseDB and BigSQL Windows installers not locking down the permissions of the PostgreSQL binary installation directory and the data directory, an unprivileged Windows user account and an unprivileged PostgreSQL account could cause the PostgreSQL service account to execute arbitrary code. This vulnerability is present in all supported versions of PostgreSQL for these installers, and possibly exists in older versions. Both sets of installers have fixed the permissions for these directories for both new and existing installations. If you have installed PostgreSQL on Windows using other methods, we advise that you check that your PostgreSQL binary directories are writable only to trusted users and that your data directories are only accessible to trusted users. The PostgreSQL project thanks Conner Jones for reporting this problem.

Fixed in this branch: 9.6.13. Component: packaging.

Official affected-branch entry: 9.6.

AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2018-1115 · Too-permissive access control list on function pg_logfile_rotate() CVSS 3.1

Fixed in this branch: 9.6.9. Component: contrib module.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2018-10925 · Memory disclosure and missing authorization in INSERT ... ON CONFLICT DO UPDATE. CVSS 7.1

Fixed in this branch: 9.6.10. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Release-note mentions:

CVE-2018-10915 · Certain host connection parameters defeat client-side security defenses CVSS 8.5

Fixed in this branch: 9.6.10. Component: client.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Release-note mentions:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
CVE-2018-1053 · pg_upgrade creates file of sensitive metadata under prevailing umask CVSS 6.7

Fixed in this branch: 9.6.7. Component: client.

Official affected-branch entry: 9.6.

AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7548 · lo_put() function ignores ACLs CVSS 3.1

Fixed in this branch: 9.6.4. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2017-7547 · pg_user_mappings view discloses passwords to users lacking server privileges CVSS 8.5
CVE-2017-7546 · empty password accepted in some authentication methods CVSS 8.1

Fixed in this branch: 9.6.4. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7486 · pg_user_mappings view discloses foreign server passwords CVSS 8.5
CVE-2017-7485 · libpq ignores PGREQUIRESSL environment variable CVSS 8.1

Fixed in this branch: 9.6.3. Component: client.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

Fixed in this branch: 9.6.3. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-15099 · INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVSS 3.1

Fixed in this branch: 9.6.6. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-15098 · Memory disclosure in JSON functions CVSS 4.3

Fixed in this branch: 9.6.6. Component: core server.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-12172 · Start scripts permit database administrator to modify root-owned files CVSS 8.4

Fixed in this branch: 9.6.6. Component: contrib module.

Official affected-branch entry: 9.6.

AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Release-note mentions:

CVE-2007-2138 · A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

Export this branch as JSON · Compare any two indexed releases