{"Entry":{"collection":"guc","key":"ignore_checksum_failure","name":"ignore_checksum_failure","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Developer Options","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"9.2","status":"added","to":"9.3"},{"documentation_changed":true,"fields":{},"from":"14","status":"changed","to":"15"}],"content_hash":"79fbee8f35298b2ade40562ed5076eef17cfb687c209db5128ea9fe63b84a6d5","context":"","default_changed_in":[],"default_history":[{"from":"9.3","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Read-only analytics does not make ignore_checksum_failure safe: corrupted pages can still poison results or structures. Use only on a disposable salvage copy with explicit acceptance of lost data.","oltp":"Never use ignore_checksum_failure as tuning or a steady-state availability setting. Stop writes, preserve immutable copies, exhaust backup/storage repair, document expected data loss, salvage narrowly, rebuild, and validate before any return to service.","small":"Do not enable ignore_checksum_failure merely because no replica exists. Preserve the original first and seek a clean backup; this switch can convert visible corruption into silent loss."},"mechanism":["With data checksums enabled, a page checksum mismatch normally aborts the current transaction. ignore_checksum_failure instead emits a warning and attempts to continue if the page header is still sane.","It does not repair the page or prove remaining tuples are valid. Continuing can crash, hide or propagate corruption, and a damaged header still stops access.","The only defensible use is controlled data salvage from an immutable copy after storage and backup recovery options are exhausted. Every read under this mode is suspect evidence, not restored integrity. Its superuser context permits an authorized session change without a server restart."],"pitfalls":["Leaving ignore_checksum_failure enabled after the bounded diagnostic or recovery task.","Running the experiment on the only copy of production data.","Underestimating log, core-file, temporary-file, WAL, CPU, or connection-slot amplification.","Treating a server that merely starts or completes a query as proof that data and behavior are correct."],"references":[{"title":"PostgreSQL 19 Beta 4: ignore_checksum_failure","url":"https://www.postgresql.org/docs/19/runtime-config-developer.html#GUC-IGNORE-CHECKSUM-FAILURE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["zero_damaged_pages","ignore_invalid_pages","data_checksums","wal_consistency_checking"],"summary":"ignore_checksum_failure — Continues processing after a checksum failure. Observed in PG9.3–19 Beta 4; its last measured boot default is off in PG19 Beta 4, with superuser context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"9.3","group":"Developer Options","group_slug":"developer","imported_at":"2026-09-27T17:57:31.386403+08:00","intro_commit":{"authored_at":"2013-03-22T13:54:07Z","discussion":[],"hash":"96ef3b8ff1cf1950e897fd2f766d4bd9ef0d5d56","subject":"Allow I/O reliability checks using 16-bit checksums","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=96ef3b8ff1cf1950e897fd2f766d4bd9ef0d5d56"},"key":"ignore_checksum_failure","last_version":"20","max_val":"","min_val":"","name":"ignore_checksum_failure","position":176,"present_in":["9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Only has effect if data checksums are enabled.","short_desc_zh":"","source_rev":"english-manuals:5f57a2f81e638bdc58ff5a52005319b99bf678324087bcd11b2fce292b83a233","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"ignore_checksum_failure","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ignore_checksum_failure","SourceRevision":"english-manuals:5f57a2f81e638bdc58ff5a52005319b99bf678324087bcd11b2fce292b83a233","Facts":{"boot_val":"off","category":"Developer Options","context":"superuser","description":"Only has effect if data checksums are enabled. Detection of a checksum failure during a read normally causes PostgreSQL to report an error, aborting the current transaction. Setting ignore_checksum_failure to on causes the system to ignore the failure (but still report a warning), and continue processing. This behavior may cause crashes, propagate or hide corruption, or other serious problems. However, it may allow you to get past the error and retrieve undamaged tuples that might still be present in the table if the block header is still sane. If the header is corrupt an error will be reported even if this option is enabled. The default setting is off. Only superusers and users with the appropriate SET privilege can change this setting.","doc":{"anchor":"GUC-IGNORE-CHECKSUM-FAILURE","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Detection of a checksum failure normally causes PostgreSQL to report an error, aborting the current transaction. Setting ignore_checksum_failure to true causes the system to ignore the failure (but still report a warning), and continue processing. This behavior could cause crashes or other serious problems. Only has an effect if checksums are enabled.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ignore_checksum_failure","short_desc":"Continues processing after a checksum failure.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-IGNORE-CHECKSUM-FAILURE","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ignore_checksum_failure","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"ignore_checksum_failure","Summary":"","BodyHTML":"\u003cp\u003e只有启用\u003ca href=\"/docs/18/checksums.html\" rel=\"nofollow\"\u003e数据校验和\u003c/a\u003e时才有效。\u003c/p\u003e\u003cp\u003e在读取过程中检测到校验和失败通常会导致\u003cspan\u003ePostgreSQL\u003c/span\u003e报告错误，中止当前事务。将\u003ccode\u003eignore_checksum_failure\u003c/code\u003e设置为 on 会使系统忽略失败（但仍报告警告），并继续处理。这种行为可能\u003cspan\u003e\u003cem\u003e导致崩溃、传播或隐藏损坏，或引发其他严重问题\u003c/em\u003e\u003c/span\u003e。但是，如果块首部仍然正常，它可能允许你跳过错误，检索表中可能仍然存在的未损坏元组。如果首部损坏，即使启用此选项也会报告错误。默认设置为\u003ccode\u003eoff\u003c/code\u003e。只有超级用户和具有适当\u003ccode\u003eSET\u003c/code\u003e权限的用户才能更改此设置。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"e0f64b4ff443be6d702f832288dcc6bec8b462176883eb77e00d5a011c50c28f","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e只有启用\u003ca href=\"/docs/18/checksums.html\" title=\"28.2. 数据校验和\"\u003e数据校验和\u003c/a\u003e时才有效。\u003c/p\u003e\u003cp\u003e在读取过程中检测到校验和失败通常会导致\u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e报告错误，中止当前事务。将\u003ccode class=\"varname\"\u003eignore_checksum_failure\u003c/code\u003e设置为 on 会使系统忽略失败（但仍报告警告），并继续处理。这种行为可能\u003cspan class=\"emphasis\"\u003e\u003cem\u003e导致崩溃、传播或隐藏损坏，或引发其他严重问题\u003c/em\u003e\u003c/span\u003e。但是，如果块首部仍然正常，它可能允许你跳过错误，检索表中可能仍然存在的未损坏元组。如果首部损坏，即使启用此选项也会报告错误。默认设置为\u003ccode class=\"literal\"\u003eoff\u003c/code\u003e。只有超级用户和具有适当\u003ccode class=\"literal\"\u003eSET\u003c/code\u003e权限的用户才能更改此设置。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
