{"Entry":{"collection":"guc","key":"pre_auth_delay","name":"pre_auth_delay","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Developer Options","category_zh":"","changed_in":["15"],"changes":[{"documentation_changed":true,"fields":{},"from":"8.1","status":"changed","to":"8.2"},{"documentation_changed":true,"fields":{},"from":"8.4","status":"changed","to":"9.0"},{"documentation_changed":true,"fields":{},"from":"11","status":"changed","to":"12"},{"documentation_changed":false,"fields":{"short_desc":{"from":"Waits N seconds on connection startup before authentication.","to":"Sets the amount of time to wait before authentication on connection startup."}},"from":"14","status":"changed","to":"15"}],"content_hash":"f36651bb02dd9754dfc3557cba4229846082e04e2e580e690d612c51b464cb32","context":"","default_changed_in":[],"default_history":[{"from":"9.0","to":"19","value":"0 s"}],"editorial":{"advice":{"olap":"Long analytical runs can amplify pre_auth_delay's debug overhead and artifacts. Prefer standard EXPLAIN and statistics first, and isolate any developer experiment from normal users.","oltp":"Do not tune production OLTP with pre_auth_delay. Enable it only for a bounded reproduction with an owner, log/disk budget, rollback condition, and evidence-capture plan; restore the default immediately afterward.","small":"Keep pre_auth_delay at its upstream default. A small host has less spare CPU, disk, connection, and log capacity for developer instrumentation."},"mechanism":["pre_auth_delay pauses a newly forked server process before authentication so a developer can attach a debugger to handshake and authentication code. Zero disables it.","The SIGHUP setting applies to future connection startups. While a process sleeps, the client is unauthenticated and a server process and connection slot can remain occupied.","It intentionally delays every affected connection and can amplify denial-of-service exposure. It is not a replacement for authentication_timeout or network rate limiting. Its SIGHUP context allows configuration reload without a server restart."],"pitfalls":["Leaving pre_auth_delay enabled after the bounded diagnostic or recovery task.","Running the experiment on the only copy of production data.","Underestimating log, core-file, temporary-file, WAL, CPU, or connection-slot amplification.","Treating a server that merely starts or completes a query as proof that data and behavior are correct."],"references":[{"title":"PostgreSQL 19 Beta 4: pre_auth_delay","url":"https://www.postgresql.org/docs/19/runtime-config-developer.html#GUC-PRE-AUTH-DELAY"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["post_auth_delay","authentication_timeout","max_connections","trace_connection_negotiation"],"summary":"pre_auth_delay — Sets the amount of time to wait before authentication on connection startup. Observed in PG9.0–19 Beta 4; its last measured boot default is 0 s in PG19 Beta 4, with sighup context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"7.4","group":"Developer Options","group_slug":"developer","imported_at":"2026-09-27T17:57:31.837205+08:00","intro_commit":{},"key":"pre_auth_delay","last_version":"20","max_val":"","min_val":"","name":"pre_auth_delay","position":314,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"The amount of time to delay just after a new server process is forked, before it conducts the authentication procedure.","short_desc_zh":"","source_rev":"english-manuals:7b3f4b2a0d8aef817eace28b9a6894dd2ab6c92eda5958655a9ab539947ba2ef","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"pre_auth_delay","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"pre_auth_delay","SourceRevision":"english-manuals:7b3f4b2a0d8aef817eace28b9a6894dd2ab6c92eda5958655a9ab539947ba2ef","Facts":{"boot_val":"0","category":"Developer Options","context":"sighup","description":"The amount of time to delay just after a new server process is forked, before it conducts the authentication procedure. This is intended to give developers an opportunity to attach to the server process with a debugger to trace down misbehavior in authentication. If this value is specified without units, it is taken as seconds. A value of zero (the default) disables the delay. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-PRE-AUTH-DELAY","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"This allows attaching a debugger to the process.","lang":"en","max_val":"60","metadata_version":"18","min_val":"0","name":"pre_auth_delay","short_desc":"Sets the amount of time to wait before authentication on connection startup.","source":"pg-settings-source-snapshot","unit":"s","vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-PRE-AUTH-DELAY","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"pre_auth_delay","SourceDatabase":"center","Version":"18","Locale":"en","Title":"pre_auth_delay","Summary":"The amount of time to delay just after a new server process is forked, before it conducts the authentication procedure. This is intended to give developers an opportunity to attach to the server process with a debugger to trace down misbehavior in authentication. If this value is specified without units, it is taken as seconds. A value of zero (the default) disables the delay. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eThe amount of time to delay just after a new server process is forked, before it conducts the authentication procedure. This is intended to give developers an opportunity to attach to the server process with a debugger to trace down misbehavior in authentication. If this value is specified without units, it is taken as seconds. A value of zero (the default) disables the delay. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:7b3f4b2a0d8aef817eace28b9a6894dd2ab6c92eda5958655a9ab539947ba2ef","ContentHash":"8aee552ffed672c73511f395575090d97c090857731e0cba5de73dd80685ed8d","Payload":{"description":"The amount of time to delay just after a new server process is forked, before it conducts the authentication procedure. This is intended to give developers an opportunity to attach to the server process with a debugger to trace down misbehavior in authentication. If this value is specified without units, it is taken as seconds. A value of zero (the default) disables the delay. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
