{"Entry":{"collection":"guc","key":"output_plugin_libraries","name":"output_plugin_libraries","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Replication / Sending Servers","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"13","status":"added","to":"14"}],"content_hash":"2a626b35b0cbb5668d484332f969ef62acfaf963635d2a0186c7ebf4fed3e2dc","context":"","default_changed_in":[],"default_history":[{"from":"14","to":"19","value":"pgoutput, test_decoding"}],"editorial":{"advice":{"olap":"ETL decoding plugins are still in-process code; do not use broad paths for convenience. Test large-transaction memory, WAL retention, and plugin output.","oltp":"List only installed, audited output plugins with a real consumer. Test with a least-privilege replication role and include plugin upgrades in the server release process.","small":"Keep the small built-in allowlist without logical decoding. Before adding wal2json or another plugin, establish package provenance, version compatibility, and maintenance ownership."},"mechanism":["Lists libraries that may be named as logical decoding output plugins. A superuser or a role granted SET privilege can change it for the relevant session or configuration scope.","Logical decoding accepts only output-plugin library names on this server-side allowlist, using LOAD-style naming with an exact plugin-name match. Adding a library is a trust decision because plugin code executes inside the server process.","Monitor and change output_plugin_libraries together with wal_level, max_wal_senders, max_replication_slots. Validate on the relevant server role and real workload, then use its superuser context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Changing it on the wrong primary, standby, sender, or subscriber role.","Watching only configured bytes/time instead of actual lag, slot position, and worker state.","Failing over to a node that lacks the old primary's capacity or prerequisites.","Using infinite waits or WAL retention to hide a failed consumer."],"references":[{"title":"PostgreSQL 19 Beta 4: output_plugin_libraries","url":"https://www.postgresql.org/docs/19/runtime-config-replication.html#GUC-OUTPUT-PLUGIN-LIBRARIES"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["wal_level","max_wal_senders","max_replication_slots","archive_mode","wal_log_hints","shared_preload_libraries"],"summary":"output_plugin_libraries lists libraries that may be named as logical decoding output plugins. It is a superuser setting present in PG14–18; the latest recorded boot default is pgoutput, test_decoding."},"enumvals":[],"first_version":"14","group":"Replication","group_slug":"replication","imported_at":"2026-09-27T17:57:31.806043+08:00","intro_commit":{"authored_at":"2026-08-10T06:38:36-07:00","discussion":[],"hash":"bf3842a64f5df489fab31b82aaeb9067ac938fde","subject":"Add an output_plugin_libraries GUC to bless trusted output plugins","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=bf3842a64f5df489fab31b82aaeb9067ac938fde"},"key":"output_plugin_libraries","last_version":"20","max_val":"","min_val":"","name":"output_plugin_libraries","position":305,"present_in":["14","15","16","17","18","19","20"],"short_desc":"Lists the libraries installed in dynamic_library_path that are also trusted for use as logical output plugins by replication clients.","short_desc_zh":"","source_rev":"english-manuals:28cee2fac0b626e9429665f078b824188537ef4462f8c405295cb15621848f04","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"output_plugin_libraries","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"output_plugin_libraries","SourceRevision":"english-manuals:28cee2fac0b626e9429665f078b824188537ef4462f8c405295cb15621848f04","Facts":{"boot_val":"pgoutput, test_decoding","category":"Replication / Sending Servers","context":"superuser","description":"Lists the libraries installed in dynamic_library_path that are also trusted for use as logical output plugins by replication clients. Any logical decoding or replication requests for other libraries will be refused. All users are subject to this restriction. The default is 'pgoutput, test_decoding', which are the two logical output plugins included in the standard PostgreSQL distribution. The format is a comma-separated list of library names, where each name is interpreted as for the LOAD command (but logical decoding clients must specify a plugin name that exactly matches an entry in the list, without variations in case or path structure). Whitespace between entries is ignored; surround a library name with double quotes if you need to include whitespace or commas in the name. It is the responsibility of the server administrator to ensure that libraries added to this list do not unintentionally give additional privileges to non-superusers when they are loaded into the server. Note When updating the server from a version that does not have the output_plugin_libraries parameter, the following query can help construct the list of plugins that are required by all persistent logical replication slots: SELECT DISTINCT plugin FROM pg_replication_slots WHERE plugin IS NOT NULL; Review the list carefully for safety before adjusting output_plugin_libraries. The above query can only display plugins which were successfully added to replication slots at some point in the past. Newly refused requests will appear in the logs with a message similar to ERROR: library \"...\" may not be used as an output plugin DETAIL: The configuration parameter \"output_plugin_libraries\" (currently 'pgoutput, test_decoding') does not name this library as a trusted output plugin. HINT: If it is safe for all REPLICATION users to use this library as an output plugin, add it to \"output_plugin_libraries\" and reload the server configuration.","doc":{"anchor":"GUC-OUTPUT-PLUGIN-LIBRARIES","file":"runtime-config-replication.html","lang":"en","sha256":"c78480a202f8579e2655e080060afe4859c9eb26a16318fb9099dabb178fb32d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Users with REPLICATION privileges may only use plugins in this list when creating logical replication slots.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"output_plugin_libraries","short_desc":"Lists libraries that may be named as logical decoding output plugins.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-OUTPUT-PLUGIN-LIBRARIES","file":"runtime-config-replication.html","lang":"en","sha256":"c78480a202f8579e2655e080060afe4859c9eb26a16318fb9099dabb178fb32d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"output_plugin_libraries","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"output_plugin_libraries","Summary":"","BodyHTML":"\u003cp\u003e列出安装在\u003ca href=\"/docs/18/runtime-config-client.html#GUC-DYNAMIC-LIBRARY-PATH\" rel=\"nofollow\"\u003edynamic_library_path\u003c/a\u003e所指定位置中、同时也受信任、可供复制客户端用作逻辑输出插件的库。任何针对其他库的\u003ca href=\"/docs/18/logicaldecoding-example.html\" rel=\"nofollow\"\u003e逻辑解码\u003c/a\u003e或\u003ca href=\"/docs/18/protocol-replication.html\" rel=\"nofollow\"\u003e复制\u003c/a\u003e请求都将被拒绝。所有用户都受此限制。默认值为 \u003ccode\u003e\u0026#39;pgoutput, test_decoding\u0026#39;\u003c/code\u003e，它们是标准 \u003cspan\u003ePostgreSQL\u003c/span\u003e 发行版中包含的两个逻辑输出插件。\u003c/p\u003e\u003cp\u003e其格式为以逗号分隔的库名称列表，每个名称的解释方式与 \u003ca href=\"/docs/18/sql-load.html\" title=\"LOAD\" rel=\"nofollow\"\u003e\u003ccode\u003eLOAD\u003c/code\u003e\u003c/a\u003e命令相同（但逻辑解码客户端指定的插件名称必须与列表中的一个条目\u003cspan\u003e\u003cem\u003e完全\u003c/em\u003e\u003c/span\u003e匹配，大小写或路径结构不得有变化）。条目之间的空白会被忽略；如果库名称中需要包含空白或逗号，请用双引号将其括起。\u003c/p\u003e\u003cp\u003e服务器管理员有责任确保，加载添加到此列表中的库时，不会无意中向非超级用户授予额外权限。\u003c/p\u003e\u003cdiv\u003e\n注意\u003cp\u003e从没有 \u003ccode\u003eoutput_plugin_libraries\u003c/code\u003e 参数的版本更新服务器时，以下查询可帮助构造所有持久逻辑复制槽所需的插件列表：\u003c/p\u003e\u003cpre\u003eSELECT DISTINCT plugin FROM pg_replication_slots WHERE plugin IS NOT NULL;\n\u003c/pre\u003e\u003cp\u003e调整 \u003ccode\u003eoutput_plugin_libraries\u003c/code\u003e 之前，请仔细审查该列表以确保安全。\u003c/p\u003e\u003cp\u003e上述查询只能显示过去某个时刻已成功添加到复制槽的插件。新近被拒绝的请求将以类似以下消息出现在日志中：\u003c/p\u003e\u003cpre\u003eERROR:  library \u0026#34;...\u0026#34; may not be used as an output plugin\nDETAIL:  The configuration parameter \u0026#34;output_plugin_libraries\u0026#34; (currently \u0026#39;pgoutput, test_decoding\u0026#39;) does not name this library as a trusted output plugin.\nHINT:  If it is safe for all REPLICATION users to use this library as an output plugin, add it to \u0026#34;output_plugin_libraries\u0026#34; and reload the server configuration.\n\u003c/pre\u003e\u003c/div\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"1298a4be29378201ae832e451b367af7f8d57c361530a59fdd8b66698ddb9923","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e列出安装在\u003ca href=\"/docs/18/runtime-config-client.html#GUC-DYNAMIC-LIBRARY-PATH\"\u003edynamic_library_path\u003c/a\u003e所指定位置中、同时也受信任、可供复制客户端用作逻辑输出插件的库。任何针对其他库的\u003ca href=\"/docs/18/logicaldecoding-example.html\" title=\"47.1. 逻辑解码示例\"\u003e逻辑解码\u003c/a\u003e或\u003ca href=\"/docs/18/protocol-replication.html\" title=\"54.4. 流复制协议\"\u003e复制\u003c/a\u003e请求都将被拒绝。所有用户都受此限制。默认值为 \u003ccode class=\"literal\"\u003e'pgoutput, test_decoding'\u003c/code\u003e，它们是标准 \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e 发行版中包含的两个逻辑输出插件。\u003c/p\u003e\u003cp\u003e其格式为以逗号分隔的库名称列表，每个名称的解释方式与 \u003ca href=\"/docs/18/sql-load.html\" title=\"LOAD\"\u003e\u003ccode class=\"command\"\u003eLOAD\u003c/code\u003e\u003c/a\u003e命令相同（但逻辑解码客户端指定的插件名称必须与列表中的一个条目\u003cspan class=\"emphasis\"\u003e\u003cem\u003e完全\u003c/em\u003e\u003c/span\u003e匹配，大小写或路径结构不得有变化）。条目之间的空白会被忽略；如果库名称中需要包含空白或逗号，请用双引号将其括起。\u003c/p\u003e\u003cp\u003e服务器管理员有责任确保，加载添加到此列表中的库时，不会无意中向非超级用户授予额外权限。\u003c/p\u003e\u003cdiv class=\"note\"\u003e\n注意\u003cp\u003e从没有 \u003ccode class=\"literal\"\u003eoutput_plugin_libraries\u003c/code\u003e 参数的版本更新服务器时，以下查询可帮助构造所有持久逻辑复制槽所需的插件列表：\u003c/p\u003e\u003cpre\u003eSELECT DISTINCT plugin FROM pg_replication_slots WHERE plugin IS NOT NULL;\n\u003c/pre\u003e\u003cp\u003e调整 \u003ccode class=\"literal\"\u003eoutput_plugin_libraries\u003c/code\u003e 之前，请仔细审查该列表以确保安全。\u003c/p\u003e\u003cp\u003e上述查询只能显示过去某个时刻已成功添加到复制槽的插件。新近被拒绝的请求将以类似以下消息出现在日志中：\u003c/p\u003e\u003cpre\u003eERROR:  library \"...\" may not be used as an output plugin\nDETAIL:  The configuration parameter \"output_plugin_libraries\" (currently 'pgoutput, test_decoding') does not name this library as a trusted output plugin.\nHINT:  If it is safe for all REPLICATION users to use this library as an output plugin, add it to \"output_plugin_libraries\" and reload the server configuration.\n\u003c/pre\u003e\u003c/div\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["14","15","16","17","18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
