{"Entry":{"collection":"guc","key":"log_parameter_max_length_on_error","name":"log_parameter_max_length_on_error","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Reporting and Logging / What to Log","category_zh":"","changed_in":["15","18"],"changes":[{"documentation_changed":false,"fields":{},"from":"12","status":"added","to":"13"},{"documentation_changed":false,"fields":{"short_desc":{"from":"When reporting an error, limit logged parameter values to first N bytes.","to":"Sets the maximum length in bytes of data logged for bind parameter values when logging statements, on error."}},"from":"14","status":"changed","to":"15"},{"documentation_changed":false,"fields":{"extra_desc":{"from":"-1 to print values in full.","to":"-1 means log values in full."}},"from":"17","status":"changed","to":"18"}],"content_hash":"ace1af2708b49b4075325406050fa7a41eea0efe24f11ec76049a2d067b42287","context":"","default_changed_in":[],"default_history":[{"from":"13","to":"19","value":"0 B"}],"editorial":{"advice":{"olap":"Use a bounded positive limit only during controlled diagnosis of parameterized analytical jobs. Budget textual conversion and retained parameter memory for successful statements as well as failures.","oltp":"Keep zero unless error diagnosis specifically requires bind values. Any nonzero value adds conversion and retained-memory work to every statement, so prefer a bounded positive value scoped by role, database, or session.","small":"Prefer zero. If error-path binds are essential, choose a short limit, scope it narrowly, and verify both memory overhead and secret-redaction policy before enabling it."},"mechanism":["log_parameter_max_length_on_error controls Bind values included in error reports. Zero, the default, suppresses them; -1 permits complete values; a positive byte count truncates each textual value to that limit.","For any nonzero value PostgreSQL must preserve textual parameter representations at the start of every statement in case an error occurs. That overhead is paid even by successful statements, and binary parameters require conversion rather than a simple text copy.","It is a USER-context session setting and is independent of log_parameter_max_length, so an application can accidentally expose values on errors even when normal statement logging suppresses them. Error detail, access, redaction, and retention must be reviewed together."],"pitfalls":["Assuming the conversion and memory cost is paid only when a statement fails; every statement pays it when the value is nonzero.","Using -1 and exposing complete secrets or large payloads in error reports.","Ignoring textual conversion cost for binary Bind values and retained representations for successful statements.","Assuming log_parameter_max_length also protects error paths; the two limits are independent."],"references":[{"title":"PostgreSQL 19 Beta 4: log_parameter_max_length_on_error","url":"https://www.postgresql.org/docs/19/runtime-config-logging.html#GUC-LOG-PARAMETER-MAX-LENGTH-ON-ERROR"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["log_statement","log_duration","log_connections","log_disconnections","log_parameter_max_length"],"summary":"log_parameter_max_length_on_error is the PostgreSQL setting that defines the maximum length in bytes of data logged for bind parameter values when logging statements, on error."},"enumvals":[],"first_version":"13","group":"Reporting and Logging","group_slug":"logging","imported_at":"2026-09-30T00:40:57.394859+08:00","intro_commit":{"authored_at":"2020-04-02T15:04:51-04:00","discussion":["https://postgr.es/m/b10493cc-a399-a03a-67c7-068f2791ee50@imap.cc"],"hash":"0b34e7d307e6a142ee94800e6d5f3e73449eeffd","subject":"Improve user control over truncation of logged bind-parameter values.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=0b34e7d307e6a142ee94800e6d5f3e73449eeffd"},"key":"log_parameter_max_length_on_error","last_version":"20","max_val":"","min_val":"","name":"log_parameter_max_length_on_error","position":238,"present_in":["13","14","15","16","17","18","19","20"],"short_desc":"If greater than zero, each bind parameter value reported in error messages is trimmed to this many bytes.","short_desc_zh":"","source_rev":"english-manuals:29452938e32975be97b86d8ed9e7b431a07b563730203b102f0033b554603a29","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"log_parameter_max_length_on_error","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"log_parameter_max_length_on_error","SourceRevision":"english-manuals:29452938e32975be97b86d8ed9e7b431a07b563730203b102f0033b554603a29","Facts":{"boot_val":"0","category":"Reporting and Logging / What to Log","context":"user","description":"If greater than zero, each bind parameter value reported in error messages is trimmed to this many bytes. Zero (the default) disables including bind parameters in error messages. -1 allows bind parameters to be printed in full. If this value is specified without units, it is taken as bytes. Non-zero values of this setting add overhead, as PostgreSQL will need to store textual representations of parameter values in memory at the start of each statement, whether or not an error eventually occurs. The overhead is greater when bind parameters are sent in binary form than when they are sent as text, since the former case requires data conversion while the latter only requires copying the string.","doc":{"anchor":"GUC-LOG-PARAMETER-MAX-LENGTH-ON-ERROR","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"-1 means log values in full.","lang":"en","max_val":"1073741823","metadata_version":"18","min_val":"-1","name":"log_parameter_max_length_on_error","short_desc":"Sets the maximum length in bytes of data logged for bind parameter values when logging statements, on error.","source":"pg-settings-source-snapshot","unit":"B","vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-LOG-PARAMETER-MAX-LENGTH-ON-ERROR","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"log_parameter_max_length_on_error","SourceDatabase":"center","Version":"18","Locale":"en","Title":"log_parameter_max_length_on_error","Summary":"If greater than zero, each bind parameter value reported in error messages is trimmed to this many bytes. Zero (the default) disables including bind parameters in error messages. -1 allows bind parameters to be printed in full. If this value is specified without units, it is taken as bytes. Non-zero values of this setting add overhead, as PostgreSQL will need to store textual representations of parameter values in memory at the start of each statement, whether or not an error eventually occurs. The overhead is greater when bind parameters are sent in binary form than when they are sent as text, since the former case requires data conversion while the latter only requires copying the string.","BodyHTML":"\u003cp\u003eIf greater than zero, each bind parameter value reported in error messages is trimmed to this many bytes. Zero (the default) disables including bind parameters in error messages. -1 allows bind parameters to be printed in full. If this value is specified without units, it is taken as bytes. Non-zero values of this setting add overhead, as PostgreSQL will need to store textual representations of parameter values in memory at the start of each statement, whether or not an error eventually occurs. The overhead is greater when bind parameters are sent in binary form than when they are sent as text, since the former case requires data conversion while the latter only requires copying the string.\u003c/p\u003e","SourceRevision":"english-manuals:29452938e32975be97b86d8ed9e7b431a07b563730203b102f0033b554603a29","ContentHash":"0ee15c3299f3a31b210abd7d6a5db458251b9a72de122e38b72bc0055f365303","Payload":{"description":"If greater than zero, each bind parameter value reported in error messages is trimmed to this many bytes. Zero (the default) disables including bind parameters in error messages. -1 allows bind parameters to be printed in full. If this value is specified without units, it is taken as bytes. Non-zero values of this setting add overhead, as PostgreSQL will need to store textual representations of parameter values in memory at the start of each statement, whether or not an error eventually occurs. The overhead is greater when bind parameters are sent in binary form than when they are sent as text, since the former case requires data conversion while the latter only requires copying the string."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
