{"Entry":{"collection":"guc","key":"restart_after_crash","name":"restart_after_crash","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Error Handling","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"9.0","status":"added","to":"9.1"},{"documentation_changed":true,"fields":{},"from":"9.5","status":"changed","to":"9.6"},{"documentation_changed":true,"fields":{},"from":"11","status":"changed","to":"12"}],"content_hash":"879ec5059145cb1bc0f35ce4654e46f6d49de259b216985909a9ba675bec4764","context":"","default_changed_in":[],"default_history":[{"from":"9.1","to":"19","value":"on"}],"editorial":{"advice":{"olap":"Test separately under long queries, batch jobs, and peak concurrency rather than copying OLTP assumptions to analytical nodes.","oltp":"Change restart_after_crash only from an explicit failure model and measured evidence. Validate in a session/test environment, deploy according to its context, and retain a rollback value.","small":"Keep the default without a concrete problem; small systems should not trade global compatibility or failure semantics for a marginal gain."},"mechanism":["Reinitialize server after backend crash. A configuration reload applies a new value; existing work already in flight is not retroactively changed.","After a backend crash, the default postmaster behavior terminates sibling backends, performs crash recovery, and resumes service. Turning this off leaves restart policy to an external supervisor and converts one backend failure into a full service stop.","Monitor and change restart_after_crash together with data_sync_retry, recovery_init_sync_method, fsync. Validate on the relevant server role and real workload, then use its sighup context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Confusing the boot default of restart_after_crash with its current effective value.","Ignoring its sighup context when deciding when it takes effect.","Changing several interacting settings at once and losing causal evidence.","Rolling out globally without testing the real failure or workload boundary."],"references":[{"title":"PostgreSQL 19 Beta 4: restart_after_crash","url":"https://www.postgresql.org/docs/19/runtime-config-error-handling.html#GUC-RESTART-AFTER-CRASH"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["data_sync_retry","recovery_init_sync_method","fsync","full_page_writes","exit_on_error","statement_timeout"],"summary":"restart_after_crash — Reinitialize server after backend crash. Observed in PG9.1–19 Beta 4; its last measured boot default is on in PG19 Beta 4, with sighup context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"9.1","group":"Error Handling","group_slug":"error-handling","imported_at":"2026-09-27T17:57:31.9104+08:00","intro_commit":{"authored_at":"2010-07-20T00:47:53Z","discussion":[],"hash":"5ffaa9005c451330bcde29d11a9385c0900ee707","subject":"Add restart_after_crash GUC.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5ffaa9005c451330bcde29d11a9385c0900ee707"},"key":"restart_after_crash","last_version":"20","max_val":"","min_val":"","name":"restart_after_crash","position":341,"present_in":["9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"When set to on, which is the default, PostgreSQL will automatically reinitialize after a backend crash.","short_desc_zh":"","source_rev":"english-manuals:78e380c57e210925bcb9403610afaf1b790d3c7cfb07ae176deb27361f5dc118","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"restart_after_crash","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"restart_after_crash","SourceRevision":"english-manuals:78e380c57e210925bcb9403610afaf1b790d3c7cfb07ae176deb27361f5dc118","Facts":{"boot_val":"on","category":"Error Handling","context":"sighup","description":"When set to on, which is the default, PostgreSQL will automatically reinitialize after a backend crash. Leaving this value set to on is normally the best way to maximize the availability of the database. However, in some circumstances, such as when PostgreSQL is being invoked by clusterware, it may be useful to disable the restart so that the clusterware can gain control and take any actions it deems appropriate. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-RESTART-AFTER-CRASH","file":"runtime-config-error-handling.html","lang":"en","sha256":"9819b00085eb96d651c6f6c3d42e9f4f9072fede4729c95234efd6d29dd41d28","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"restart_after_crash","short_desc":"Reinitialize server after backend crash.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-RESTART-AFTER-CRASH","file":"runtime-config-error-handling.html","lang":"en","sha256":"9819b00085eb96d651c6f6c3d42e9f4f9072fede4729c95234efd6d29dd41d28","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"restart_after_crash","SourceDatabase":"center","Version":"18","Locale":"en","Title":"restart_after_crash","Summary":"When set to on, which is the default, PostgreSQL will automatically reinitialize after a backend crash. Leaving this value set to on is normally the best way to maximize the availability of the database. However, in some circumstances, such as when PostgreSQL is being invoked by clusterware, it may be useful to disable the restart so that the clusterware can gain control and take any actions it deems appropriate. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eWhen set to on, which is the default, PostgreSQL will automatically reinitialize after a backend crash. Leaving this value set to on is normally the best way to maximize the availability of the database. However, in some circumstances, such as when PostgreSQL is being invoked by clusterware, it may be useful to disable the restart so that the clusterware can gain control and take any actions it deems appropriate. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:78e380c57e210925bcb9403610afaf1b790d3c7cfb07ae176deb27361f5dc118","ContentHash":"5a790142e138d79a9fa1206cb7d9719b5cac664015607c0a8d02af0b930290c9","Payload":{"description":"When set to on, which is the default, PostgreSQL will automatically reinitialize after a backend crash. Leaving this value set to on is normally the best way to maximize the availability of the database. However, in some circumstances, such as when PostgreSQL is being invoked by clusterware, it may be useful to disable the restart so that the clusterware can gain control and take any actions it deems appropriate. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
