{"Entry":{"collection":"guc","key":"exit_on_error","name":"exit_on_error","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Error Handling","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"9.0","status":"added","to":"9.1"},{"documentation_changed":true,"fields":{},"from":"11","status":"changed","to":"12"}],"content_hash":"a58904d4bfbe5d18d7f8dacee43b67230cbe64b8b0b947b2e707f6871baed1a5","context":"","default_changed_in":[],"default_history":[{"from":"9.1","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Test separately under long queries, batch jobs, and peak concurrency rather than copying OLTP assumptions to analytical nodes.","oltp":"Change exit_on_error only from an explicit failure model and measured evidence. Validate in a session/test environment, deploy according to its context, and retain a rollback value.","small":"Keep the default without a concrete problem; small systems should not trade global compatibility or failure semantics for a marginal gain."},"mechanism":["The exit_on_error name already exists in PostgreSQL's GUC table at this project's 2008 Git-history boundary and in the PG9.0 source. PG9.0 marks it GUC_NO_SHOW_ALL, so it is absent from that version's pg_settings snapshot; first observation in PG9.1 is a visibility change, not a claim that the underlying behavior was invented in PG9.1.","When enabled, an error terminates the backend session after normal error processing, not merely the current transaction. It differs from client-side stop-on-error behavior such as psql's ON_ERROR_STOP and can discard session-local state, prepared statements, temporary objects, and an application's connection unexpectedly.","Because it has user context, a controlled session can test the policy without changing every connection. Treat it together with restart_after_crash, transaction error handling, pooler retry behavior, statement_timeout, and idle_in_transaction_session_timeout; server termination is not a substitute for correct transaction recovery."],"pitfalls":["Confusing the boot default of exit_on_error with its current effective value.","Ignoring its user context when deciding when it takes effect.","Changing several interacting settings at once and losing causal evidence.","Rolling out globally without testing the real failure or workload boundary."],"references":[{"title":"PostgreSQL 19 Beta 4: exit_on_error","url":"https://www.postgresql.org/docs/19/runtime-config-error-handling.html#GUC-EXIT-ON-ERROR"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["restart_after_crash","statement_timeout","idle_in_transaction_session_timeout","data_sync_retry","recovery_init_sync_method"],"summary":"exit_on_error — Terminate session on any error. Observed in PG9.1–19 Beta 4; its last measured boot default is off in PG19 Beta 4, with user context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"9.1","group":"Error Handling","group_slug":"error-handling","imported_at":"2026-09-27T17:57:31.259509+08:00","intro_commit":{"status":"predates_history_boundary"},"key":"exit_on_error","last_version":"20","max_val":"","min_val":"","name":"exit_on_error","position":141,"present_in":["9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"If on, any error will terminate the current session.","short_desc_zh":"","source_rev":"english-manuals:21bc626565c0c020992ad8cf50569405b4343448aa8ba99ccc8dcfb38dd91815","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"exit_on_error","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"exit_on_error","SourceRevision":"english-manuals:21bc626565c0c020992ad8cf50569405b4343448aa8ba99ccc8dcfb38dd91815","Facts":{"boot_val":"off","category":"Error Handling","context":"user","description":"If on, any error will terminate the current session. By default, this is set to off, so that only FATAL errors will terminate the session.","doc":{"anchor":"GUC-EXIT-ON-ERROR","file":"runtime-config-error-handling.html","lang":"en","sha256":"9819b00085eb96d651c6f6c3d42e9f4f9072fede4729c95234efd6d29dd41d28","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"exit_on_error","short_desc":"Terminate session on any error.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-EXIT-ON-ERROR","file":"runtime-config-error-handling.html","lang":"en","sha256":"9819b00085eb96d651c6f6c3d42e9f4f9072fede4729c95234efd6d29dd41d28","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"exit_on_error","SourceDatabase":"center","Version":"18","Locale":"en","Title":"exit_on_error","Summary":"If on, any error will terminate the current session. By default, this is set to off, so that only FATAL errors will terminate the session.","BodyHTML":"\u003cp\u003eIf on, any error will terminate the current session. By default, this is set to off, so that only FATAL errors will terminate the session.\u003c/p\u003e","SourceRevision":"english-manuals:21bc626565c0c020992ad8cf50569405b4343448aa8ba99ccc8dcfb38dd91815","ContentHash":"fa3a9d971c09ca8fcb82eca04171d040781126b339f718dda5df9731ab32f686","Payload":{"description":"If on, any error will terminate the current session. By default, this is set to off, so that only FATAL errors will terminate the session."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
