{"Entry":{"collection":"guc","key":"restrict_nonsystem_relation_kind","name":"restrict_nonsystem_relation_kind","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Client Connection Defaults / Statement Behavior","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"11","status":"added","to":"12"}],"content_hash":"d54b48249574ea8abc9f289ccd4236b0c3355232c34b98ca61afc98a73661c2e","context":"","default_changed_in":[],"default_history":[{"from":"12","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Do not use it to sandbox arbitrary analytical users; enforce access with privileges, schemas, and row-level policies.","oltp":"Do not tune restrict_nonsystem_relation_kind as a general security policy. Leave it empty unless a PostgreSQL subsystem or tightly scoped maintenance workflow explicitly requires the restriction.","small":"Keep the default empty. Enabling relation-kind bans has no capacity benefit and can break ordinary queries unexpectedly."},"mechanism":["restrict_nonsystem_relation_kind prohibits access to non-system relations of specified kinds. The supported kinds are view and foreign-table; PostgreSQL uses the restriction as a safety boundary for specialized sessions, not as general SQL authorization.","restrict_nonsystem_relation_kind is a USER-context setting. An authorized role can change it for a session, while ALTER ROLE or ALTER DATABASE can establish a default for future sessions.","Because session state can survive in pooled connections, role defaults, SET privilege, RESET behavior, and application checkout hooks are part of the control's effective boundary."],"pitfalls":["Changing restrict_nonsystem_relation_kind in one session and assuming role defaults, database defaults, or other pooled sessions changed with it.","Granting broad SET rights to a control that can change correctness, policy enforcement, or name resolution.","Failing to reset a security-sensitive session value before a pooled connection is reused by another request.","Changing restrict_nonsystem_relation_kind globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: restrict_nonsystem_relation_kind","url":"https://www.postgresql.org/docs/19/runtime-config-client.html#GUC-RESTRICT-NONSYSTEM-RELATION-KIND"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["search_path","row_security","session_replication_role","event_triggers","createrole_self_grant"],"summary":"restrict_nonsystem_relation_kind is the PostgreSQL setting that prohibits access to non-system relations of specified kinds."},"enumvals":[],"first_version":"12","group":"Client Connection Defaults","group_slug":"client","imported_at":"2026-09-27T17:57:31.916483+08:00","intro_commit":{"authored_at":"2024-08-05T06:05:17-07:00","discussion":[],"hash":"79c7a7e29695a32fef2e65682be224b8d61ec972","subject":"Restrict accesses to non-system views and foreign tables during pg_dump.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=79c7a7e29695a32fef2e65682be224b8d61ec972"},"key":"restrict_nonsystem_relation_kind","last_version":"20","max_val":"","min_val":"","name":"restrict_nonsystem_relation_kind","position":343,"present_in":["12","13","14","15","16","17","18","19","20"],"short_desc":"Set relation kinds for which access to non-system relations is prohibited.","short_desc_zh":"","source_rev":"english-manuals:65e427e16a41362fb43727d296306bfd31d29bb6746cb81c492d2426634f72f6","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"restrict_nonsystem_relation_kind","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"restrict_nonsystem_relation_kind","SourceRevision":"english-manuals:65e427e16a41362fb43727d296306bfd31d29bb6746cb81c492d2426634f72f6","Facts":{"boot_val":"","category":"Client Connection Defaults / Statement Behavior","context":"user","description":"Set relation kinds for which access to non-system relations is prohibited. The value takes the form of a comma-separated list of relation kinds. Currently, the supported relation kinds are view and foreign-table.","doc":{"anchor":"GUC-RESTRICT-NONSYSTEM-RELATION-KIND","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"restrict_nonsystem_relation_kind","short_desc":"Prohibits access to non-system relations of specified kinds.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-RESTRICT-NONSYSTEM-RELATION-KIND","file":"runtime-config-client.html","lang":"en","sha256":"6be6cc70f29eca4695dc43b2b2b94c75b7e0eaaa2c00273d7a98488917a7edb7","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"restrict_nonsystem_relation_kind","SourceDatabase":"center","Version":"18","Locale":"en","Title":"restrict_nonsystem_relation_kind","Summary":"Set relation kinds for which access to non-system relations is prohibited. The value takes the form of a comma-separated list of relation kinds. Currently, the supported relation kinds are view and foreign-table.","BodyHTML":"\u003cp\u003eSet relation kinds for which access to non-system relations is prohibited. The value takes the form of a comma-separated list of relation kinds. Currently, the supported relation kinds are view and foreign-table.\u003c/p\u003e","SourceRevision":"english-manuals:65e427e16a41362fb43727d296306bfd31d29bb6746cb81c492d2426634f72f6","ContentHash":"dc1f0e916ac90013e9f667678c3d846a057768c78d31c203f8cf4c0c59b8eefc","Payload":{"description":"Set relation kinds for which access to non-system relations is prohibited. The value takes the form of a comma-separated list of relation kinds. Currently, the supported relation kinds are view and foreign-table."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
