{"Entry":{"collection":"guc","key":"vacuum_failsafe_age","name":"vacuum_failsafe_age","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Vacuuming / Freezing","category_zh":"","changed_in":["18"],"changes":[{"documentation_changed":false,"fields":{},"from":"13","status":"added","to":"14"},{"documentation_changed":true,"fields":{},"from":"15","status":"changed","to":"16"},{"documentation_changed":false,"fields":{"category":{"from":"Client Connection Defaults / Statement Behavior","to":"Vacuuming / Freezing"}},"from":"17","status":"changed","to":"18"}],"content_hash":"570fafcc0f16910fafe968cfe10331278454edfa72588040cd33a0d93c48f2d4","context":"","default_changed_in":[],"default_history":[{"from":"14","to":"19","value":"1600000000"}],"editorial":{"advice":{"olap":"Proactively VACUUM (FREEZE) newly loaded or static partitions in batch windows and reserve I/O time for full scans. Convert age budgets using peak transaction rate, not a wall-clock guess.","oltp":"Calibrate vacuum_failsafe_age against the oldest XID/MXID age in every database and measured vacuum completion rate. Remove long transactions, stale slots, and blocked workers; never raise ages merely to hide a backlog.","small":"Upstream defaults are usually safest. A small system still needs anti-wraparound maintenance; monitor every database, not only the application database."},"mechanism":["Age at which VACUUM should trigger failsafe to avoid a wraparound outage. It can be changed at session scope, so different sessions may observe different behavior.","At the failsafe age, a running VACUUM prioritizes advancing the freeze horizon quickly: cost delays stop and optional work such as index cleanup and tail truncation is skipped. This is a last defense against wraparound outage, not a routine performance mode.","Monitor and change vacuum_failsafe_age together with autovacuum_freeze_max_age, vacuum_freeze_min_age, vacuum_freeze_table_age. Validate on the relevant server role and real workload, then use its user context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Treating failsafe as a normal high-throughput VACUUM mode.","Ignoring skipped index cleanup after the emergency has passed.","Raising the age to suppress evidence of a maintenance failure.","Changing the global value while a table storage parameter overrides it.","Treating reltuples and cumulative change statistics as exact real-time counts."],"references":[{"title":"PostgreSQL 19 Beta 4: vacuum_failsafe_age","url":"https://www.postgresql.org/docs/19/runtime-config-vacuum.html#GUC-VACUUM-FAILSAFE-AGE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["autovacuum_freeze_max_age","vacuum_freeze_min_age","vacuum_freeze_table_age","autovacuum_multixact_freeze_max_age","vacuum_multixact_freeze_min_age","vacuum_multixact_freeze_table_age"],"summary":"vacuum_failsafe_age sets the age at which VACUUM should trigger failsafe to avoid a wraparound outage. It is a user setting present in PG14–18; the latest recorded boot default is 1600000000."},"enumvals":[],"first_version":"14","group":"Vacuuming","group_slug":"vacuum","imported_at":"2026-09-27T17:57:32.286077+08:00","intro_commit":{"authored_at":"2021-04-07T12:37:45-07:00","discussion":["https://postgr.es/m/CAD21AoD0SkE11fMw4jD4RENAwBMcw1wasVnwpJVw3tVqPOQgAw@mail.gmail.com","https://postgr.es/m/CAH2-WzmgH3ySGYeC-m-eOBsa2=sDwa292-CFghV4rESYo39FsQ@mail.gmail.com"],"hash":"1e55e7d1755cefbb44982fbacc7da461fa8684e6","subject":"Add wraparound failsafe to VACUUM.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=1e55e7d1755cefbb44982fbacc7da461fa8684e6"},"key":"vacuum_failsafe_age","last_version":"20","max_val":"","min_val":"","name":"vacuum_failsafe_age","position":452,"present_in":["14","15","16","17","18","19","20"],"short_desc":"Specifies the maximum age (in transactions) that a table's pg_class.relfrozenxid field can attain before VACUUM takes extraordinary measures to avoid system-wide transaction ID wraparound failure.","short_desc_zh":"","source_rev":"english-manuals:3c2b40df525de3a8ae84f869b8f73f68bb56d0229b9a098ace6a684a2de2ea1c","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"vacuum_failsafe_age","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"vacuum_failsafe_age","SourceRevision":"english-manuals:3c2b40df525de3a8ae84f869b8f73f68bb56d0229b9a098ace6a684a2de2ea1c","Facts":{"boot_val":"1600000000","category":"Vacuuming / Freezing","context":"user","description":"Specifies the maximum age (in transactions) that a table's pg_class.relfrozenxid field can attain before VACUUM takes extraordinary measures to avoid system-wide transaction ID wraparound failure. This is VACUUM's strategy of last resort. The failsafe typically triggers when an autovacuum to prevent transaction ID wraparound has already been running for some time, though it's possible for the failsafe to trigger during any VACUUM. When the failsafe is triggered, any cost-based delay that is in effect will no longer be applied, further non-essential maintenance tasks (such as index vacuuming) are bypassed, and any Buffer Access Strategy in use will be disabled resulting in VACUUM being free to make use of all of shared buffers. The default is 1.6 billion transactions. Although users can set this value anywhere from zero to 2.1 billion, VACUUM will silently adjust the effective value to no less than 105% of autovacuum_freeze_max_age.","doc":{"anchor":"GUC-VACUUM-FAILSAFE-AGE","file":"runtime-config-vacuum.html","lang":"en","sha256":"7047f1fa9138b97f1812532f8a905fa7479451dfd64655e029a7d387b20b22e4","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":"2100000000","metadata_version":"18","min_val":"0","name":"vacuum_failsafe_age","short_desc":"Age at which VACUUM should trigger failsafe to avoid a wraparound outage.","source":"pg-settings-source-snapshot","unit":null,"vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-VACUUM-FAILSAFE-AGE","file":"runtime-config-vacuum.html","lang":"en","sha256":"7047f1fa9138b97f1812532f8a905fa7479451dfd64655e029a7d387b20b22e4","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"vacuum_failsafe_age","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"vacuum_failsafe_age","Summary":"","BodyHTML":"\u003cp\u003e指定表的\u003ccode\u003epg_class\u003c/code\u003e.\u003ccode\u003erelfrozenxid\u003c/code\u003e字段在\u003ccode\u003eVACUUM\u003c/code\u003e采取非常措施以避免系统范围事务 ID 回卷失败之前所允许达到的最大年龄（以事务数计）。这是\u003ccode\u003eVACUUM\u003c/code\u003e的最后手段。失效保护通常会在为防止事务 ID 回卷而启动的自动清理已经运行一段时间后触发，但也可能在任何一次\u003ccode\u003eVACUUM\u003c/code\u003e期间触发。\u003c/p\u003e\u003cp\u003e当触发失效保护时，当前生效的任何基于代价的延迟都将不再应用，进一步的非关键维护任务（例如索引清理）会被跳过，并且正在使用的任何\u003ca href=\"/docs/18/glossary.html#GLOSSARY-BUFFER-ACCESS-STRATEGY\" rel=\"nofollow\"\u003e\u003c/a\u003e\u003ca href=\"/docs/18/glossary.html#GLOSSARY-BUFFER-ACCESS-STRATEGY\" title=\"缓冲区访问策略\" rel=\"nofollow\"\u003e缓冲区访问策略\u003c/a\u003e都会被禁用，从而使\u003ccode\u003eVACUUM\u003c/code\u003e可以自由使用全部\u003ca href=\"/docs/18/glossary.html#GLOSSARY-SHARED-MEMORY\" rel=\"nofollow\"\u003e\u003c/a\u003e\u003ca href=\"/docs/18/glossary.html#GLOSSARY-SHARED-MEMORY\" title=\"共享内存\" rel=\"nofollow\"\u003e共享缓冲区\u003c/a\u003e。\u003c/p\u003e\u003cp\u003e默认值为 16 亿个事务。尽管用户可以将该值设置在 0 到 21 亿之间，\u003ccode\u003eVACUUM\u003c/code\u003e仍会悄悄将其有效值调整为不低于\u003ca href=\"/docs/18/runtime-config-vacuum.html#GUC-AUTOVACUUM-FREEZE-MAX-AGE\" rel=\"nofollow\"\u003eautovacuum_freeze_max_age\u003c/a\u003e的 105%。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"5640f8d125b374e9af2c9e655c56e251803f5f3d5c0d0c701313ab807bda2d58","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定表的\u003ccode class=\"structname\"\u003epg_class\u003c/code\u003e.\u003ccode class=\"structfield\"\u003erelfrozenxid\u003c/code\u003e字段在\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e采取非常措施以避免系统范围事务 ID 回卷失败之前所允许达到的最大年龄（以事务数计）。这是\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e的最后手段。失效保护通常会在为防止事务 ID 回卷而启动的自动清理已经运行一段时间后触发，但也可能在任何一次\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e期间触发。\u003c/p\u003e\u003cp\u003e当触发失效保护时，当前生效的任何基于代价的延迟都将不再应用，进一步的非关键维护任务（例如索引清理）会被跳过，并且正在使用的任何\u003ca href=\"/docs/18/glossary.html#GLOSSARY-BUFFER-ACCESS-STRATEGY\"\u003e\u003c/a\u003e\u003ca href=\"/docs/18/glossary.html#GLOSSARY-BUFFER-ACCESS-STRATEGY\" title=\"缓冲区访问策略\"\u003e缓冲区访问策略\u003c/a\u003e都会被禁用，从而使\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e可以自由使用全部\u003ca href=\"/docs/18/glossary.html#GLOSSARY-SHARED-MEMORY\"\u003e\u003c/a\u003e\u003ca href=\"/docs/18/glossary.html#GLOSSARY-SHARED-MEMORY\" title=\"共享内存\"\u003e共享缓冲区\u003c/a\u003e。\u003c/p\u003e\u003cp\u003e默认值为 16 亿个事务。尽管用户可以将该值设置在 0 到 21 亿之间，\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e仍会悄悄将其有效值调整为不低于\u003ca href=\"/docs/18/runtime-config-vacuum.html#GUC-AUTOVACUUM-FREEZE-MAX-AGE\"\u003eautovacuum_freeze_max_age\u003c/a\u003e的 105%。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["14","15","16","17","18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
