{"Entry":{"collection":"guc","key":"ignore_invalid_pages","name":"ignore_invalid_pages","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Developer Options","category_zh":"","changed_in":["17"],"changes":[{"documentation_changed":false,"fields":{},"from":"12","status":"added","to":"13"},{"documentation_changed":false,"fields":{"extra_desc":{"from":"Detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting ignore_invalid_pages to true causes the system to ignore invalid page references in WAL records (but still report a warning), and continue recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. Only has an effect during recovery or in standby mode.","to":"Detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting \"ignore_invalid_pages\" to true causes the system to ignore invalid page references in WAL records (but still report a warning), and continue recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. Only has an effect during recovery or in standby mode."}},"from":"16","status":"changed","to":"17"}],"content_hash":"84fe2c3a91ea290d060c0cf25fe5ce8f8b8e5246dbe34bff29b5cbbb88a2bc09","context":"","default_changed_in":[],"default_history":[{"from":"13","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Read-only analytics does not make ignore_invalid_pages safe: corrupted pages can still poison results or structures. Use only on a disposable salvage copy with explicit acceptance of lost data.","oltp":"Never use ignore_invalid_pages as tuning or a steady-state availability setting. Stop writes, preserve immutable copies, exhaust backup/storage repair, document expected data loss, salvage narrowly, rebuild, and validate before any return to service.","small":"Do not enable ignore_invalid_pages merely because no replica exists. Preserve the original first and seek a clean backup; this switch can convert visible corruption into silent loss."},"mechanism":["During recovery, WAL references to invalid pages normally cause PANIC and stop recovery. ignore_invalid_pages logs a warning and continues past those references.","The startup-only setting has effect only in recovery or standby mode. Skipping redo can lose data, propagate corruption, and leave structures internally inconsistent even if the server reaches a running state.","It is an emergency salvage mechanism after preserving evidence and exhausting correct restore paths. A server that starts under it must not be considered healthy or promoted into normal service. Its postmaster context fixes the value at server start; changing it requires a restart."],"pitfalls":["Leaving ignore_invalid_pages enabled after the bounded diagnostic or recovery task.","Running the experiment on the only copy of production data.","Underestimating log, core-file, temporary-file, WAL, CPU, or connection-slot amplification.","Treating a server that merely starts or completes a query as proof that data and behavior are correct."],"references":[{"title":"PostgreSQL 19 Beta 4: ignore_invalid_pages","url":"https://www.postgresql.org/docs/19/runtime-config-developer.html#GUC-IGNORE-INVALID-PAGES"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ignore_checksum_failure","zero_damaged_pages","restore_command","wal_consistency_checking"],"summary":"ignore_invalid_pages — Continues recovery after an invalid pages failure. Observed in PG13–19 Beta 4; its last measured boot default is off in PG19 Beta 4, with postmaster context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"13","group":"Developer Options","group_slug":"developer","imported_at":"2026-09-27T17:57:31.389735+08:00","intro_commit":{"authored_at":"2020-01-22T11:56:34+09:00","discussion":["https://www.postgresql.org/message-id/CAHGQGwHCK6f77yeZD4MHOnN+PaTf6XiJfEB+Ce7SksSHjeAWtg@mail.gmail.com"],"hash":"41c184bc642b25f67fb1d8ee290f28805fa5a0b4","subject":"Add GUC ignore_invalid_pages.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=41c184bc642b25f67fb1d8ee290f28805fa5a0b4"},"key":"ignore_invalid_pages","last_version":"20","max_val":"","min_val":"","name":"ignore_invalid_pages","position":177,"present_in":["13","14","15","16","17","18","19","20"],"short_desc":"If set to off (the default), detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery.","short_desc_zh":"","source_rev":"english-manuals:f0da43d224bd2a27e7c06ccceab2dd6f098ca7eca37ec84fb6b2089d39978ce5","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"ignore_invalid_pages","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ignore_invalid_pages","SourceRevision":"english-manuals:f0da43d224bd2a27e7c06ccceab2dd6f098ca7eca37ec84fb6b2089d39978ce5","Facts":{"boot_val":"off","category":"Developer Options","context":"postmaster","description":"If set to off (the default), detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting ignore_invalid_pages to on causes the system to ignore invalid page references in WAL records (but still report a warning), and continue the recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. However, it may allow you to get past the PANIC-level error, to finish the recovery, and to cause the server to start up. The parameter can only be set at server start. It only has effect during recovery or in standby mode.","doc":{"anchor":"GUC-IGNORE-INVALID-PAGES","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting \"ignore_invalid_pages\" to true causes the system to ignore invalid page references in WAL records (but still report a warning), and continue recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. Only has an effect during recovery or in standby mode.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ignore_invalid_pages","short_desc":"Continues recovery after an invalid pages failure.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-IGNORE-INVALID-PAGES","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ignore_invalid_pages","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ignore_invalid_pages","Summary":"If set to off (the default), detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting ignore_invalid_pages to on causes the system to ignore invalid page references in WAL records (but still report a warning), and continue the recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. However, it may allow you to get past the PANIC-level error, to finish the recovery, and to cause the server to start up. The parameter can only be set at server start. It only has effect during recovery or in standby mode.","BodyHTML":"\u003cp\u003eIf set to off (the default), detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting ignore_invalid_pages to on causes the system to ignore invalid page references in WAL records (but still report a warning), and continue the recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. However, it may allow you to get past the PANIC-level error, to finish the recovery, and to cause the server to start up. The parameter can only be set at server start. It only has effect during recovery or in standby mode.\u003c/p\u003e","SourceRevision":"english-manuals:f0da43d224bd2a27e7c06ccceab2dd6f098ca7eca37ec84fb6b2089d39978ce5","ContentHash":"8227c528a6fb4ce7e51dc1fd9b41e1fa75bf4b76e9022eacf7e0022e43e4d395","Payload":{"description":"If set to off (the default), detection of WAL records having references to invalid pages during recovery causes PostgreSQL to raise a PANIC-level error, aborting the recovery. Setting ignore_invalid_pages to on causes the system to ignore invalid page references in WAL records (but still report a warning), and continue the recovery. This behavior may cause crashes, data loss, propagate or hide corruption, or other serious problems. However, it may allow you to get past the PANIC-level error, to finish the recovery, and to cause the server to start up. The parameter can only be set at server start. It only has effect during recovery or in standby mode."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
