{"Entry":{"collection":"guc","key":"vacuum_multixact_failsafe_age","name":"vacuum_multixact_failsafe_age","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Vacuuming / Freezing","category_zh":"","changed_in":["18"],"changes":[{"documentation_changed":false,"fields":{},"from":"13","status":"added","to":"14"},{"documentation_changed":false,"fields":{"category":{"from":"Client Connection Defaults / Statement Behavior","to":"Vacuuming / Freezing"}},"from":"17","status":"changed","to":"18"}],"content_hash":"cfa32f054c053d6747551c4f9cf825d4139faa6b3460bc9f269056714b4d64fb","context":"","default_changed_in":[],"default_history":[{"from":"14","to":"19","value":"1600000000"}],"editorial":{"advice":{"olap":"Proactively VACUUM (FREEZE) newly loaded or static partitions in batch windows and reserve I/O time for full scans. Convert age budgets using peak transaction rate, not a wall-clock guess.","oltp":"Calibrate vacuum_multixact_failsafe_age against the oldest XID/MXID age in every database and measured vacuum completion rate. Remove long transactions, stale slots, and blocked workers; never raise ages merely to hide a backlog.","small":"Upstream defaults are usually safest. A small system still needs anti-wraparound maintenance; monitor every database, not only the application database."},"mechanism":["Multixact age at which VACUUM should trigger failsafe to avoid a wraparound outage. It can be changed at session scope, so different sessions may observe different behavior.","At the failsafe age, a running VACUUM prioritizes advancing the freeze horizon quickly: cost delays stop and optional work such as index cleanup and tail truncation is skipped. This is a last defense against wraparound outage, not a routine performance mode.","Monitor and change vacuum_multixact_failsafe_age together with autovacuum_freeze_max_age, vacuum_freeze_min_age, vacuum_freeze_table_age. Validate on the relevant server role and real workload, then use its user context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Treating failsafe as routine instead of an emergency.","Monitoring only XID age and missing MXID exhaustion.","Ignoring post-failsafe index cleanup debt.","Changing the global value while a table storage parameter overrides it.","Treating reltuples and cumulative change statistics as exact real-time counts."],"references":[{"title":"PostgreSQL 19 Beta 4: vacuum_multixact_failsafe_age","url":"https://www.postgresql.org/docs/19/runtime-config-vacuum.html#GUC-VACUUM-MULTIXACT-FAILSAFE-AGE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["autovacuum_freeze_max_age","vacuum_freeze_min_age","vacuum_freeze_table_age","vacuum_failsafe_age","autovacuum_multixact_freeze_max_age","vacuum_multixact_freeze_min_age"],"summary":"vacuum_multixact_failsafe_age sets the multixact age at which VACUUM should trigger failsafe to avoid a wraparound outage. It is a user setting present in PG14–18; the latest recorded boot default is 1600000000."},"enumvals":[],"first_version":"14","group":"Vacuuming","group_slug":"vacuum","imported_at":"2026-09-27T17:57:32.299621+08:00","intro_commit":{"authored_at":"2021-04-07T12:37:45-07:00","discussion":["https://postgr.es/m/CAD21AoD0SkE11fMw4jD4RENAwBMcw1wasVnwpJVw3tVqPOQgAw@mail.gmail.com","https://postgr.es/m/CAH2-WzmgH3ySGYeC-m-eOBsa2=sDwa292-CFghV4rESYo39FsQ@mail.gmail.com"],"hash":"1e55e7d1755cefbb44982fbacc7da461fa8684e6","subject":"Add wraparound failsafe to VACUUM.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=1e55e7d1755cefbb44982fbacc7da461fa8684e6"},"key":"vacuum_multixact_failsafe_age","last_version":"20","max_val":"","min_val":"","name":"vacuum_multixact_failsafe_age","position":457,"present_in":["14","15","16","17","18","19","20"],"short_desc":"Specifies the maximum age (in multixacts) that a table's pg_class.relminmxid field can attain before VACUUM takes extraordinary measures to avoid system-wide multixact ID wraparound failure.","short_desc_zh":"","source_rev":"english-manuals:2192ef8a12f150b1f61673d0183b70d6d2881a28ac9bbdf3ca6228b54c1fd034","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"vacuum_multixact_failsafe_age","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"vacuum_multixact_failsafe_age","SourceRevision":"english-manuals:2192ef8a12f150b1f61673d0183b70d6d2881a28ac9bbdf3ca6228b54c1fd034","Facts":{"boot_val":"1600000000","category":"Vacuuming / Freezing","context":"user","description":"Specifies the maximum age (in multixacts) that a table's pg_class.relminmxid field can attain before VACUUM takes extraordinary measures to avoid system-wide multixact ID wraparound failure. This is VACUUM's strategy of last resort. The failsafe typically triggers when an autovacuum to prevent transaction ID wraparound has already been running for some time, though it's possible for the failsafe to trigger during any VACUUM. When the failsafe is triggered, any cost-based delay that is in effect will no longer be applied, and further non-essential maintenance tasks (such as index vacuuming) are bypassed. The default is 1.6 billion multixacts. Although users can set this value anywhere from zero to 2.1 billion, VACUUM will silently adjust the effective value to no less than 105% of autovacuum_multixact_freeze_max_age.","doc":{"anchor":"GUC-VACUUM-MULTIXACT-FAILSAFE-AGE","file":"runtime-config-vacuum.html","lang":"en","sha256":"7047f1fa9138b97f1812532f8a905fa7479451dfd64655e029a7d387b20b22e4","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":"2100000000","metadata_version":"18","min_val":"0","name":"vacuum_multixact_failsafe_age","short_desc":"Multixact age at which VACUUM should trigger failsafe to avoid a wraparound outage.","source":"pg-settings-source-snapshot","unit":null,"vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-VACUUM-MULTIXACT-FAILSAFE-AGE","file":"runtime-config-vacuum.html","lang":"en","sha256":"7047f1fa9138b97f1812532f8a905fa7479451dfd64655e029a7d387b20b22e4","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"vacuum_multixact_failsafe_age","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"vacuum_multixact_failsafe_age","Summary":"","BodyHTML":"\u003cp\u003e指定表的 \u003ccode\u003epg_class\u003c/code\u003e.\u003ccode\u003erelminmxid\u003c/code\u003e 字段在 \u003ccode\u003eVACUUM\u003c/code\u003e 采取特别措施避免系统范围的多事务 ID 回卷故障之前，所能达到的最大年龄（以多事务计）。这是 \u003ccode\u003eVACUUM\u003c/code\u003e 的最后手段。失效保护通常会在防止事务 ID 回卷的自动清理已经运行一段时间后触发，但也可能在任何 \u003ccode\u003eVACUUM\u003c/code\u003e 期间触发。\u003c/p\u003e\u003cp\u003e触发失效保护后，任何正在生效的基于代价的延迟都将不再应用，后续非必要的维护任务（例如索引清理）也会被跳过。\u003c/p\u003e\u003cp\u003e默认值为 16 亿个多事务。虽然用户可以将此值设置为 0 到 21 亿之间的任意值，\u003ccode\u003eVACUUM\u003c/code\u003e 仍会将实际生效值自动调整为不低于\u003ca href=\"/docs/18/runtime-config-vacuum.html#GUC-AUTOVACUUM-MULTIXACT-FREEZE-MAX-AGE\" rel=\"nofollow\"\u003eautovacuum_multixact_freeze_max_age\u003c/a\u003e的 105%。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"2e92651c6dc3e3d73490336d7eda158404e2dfbdb30dfbc18d1c64f64b673d0b","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定表的 \u003ccode class=\"structname\"\u003epg_class\u003c/code\u003e.\u003ccode class=\"structfield\"\u003erelminmxid\u003c/code\u003e 字段在 \u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e 采取特别措施避免系统范围的多事务 ID 回卷故障之前，所能达到的最大年龄（以多事务计）。这是 \u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e 的最后手段。失效保护通常会在防止事务 ID 回卷的自动清理已经运行一段时间后触发，但也可能在任何 \u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e 期间触发。\u003c/p\u003e\u003cp\u003e触发失效保护后，任何正在生效的基于代价的延迟都将不再应用，后续非必要的维护任务（例如索引清理）也会被跳过。\u003c/p\u003e\u003cp\u003e默认值为 16 亿个多事务。虽然用户可以将此值设置为 0 到 21 亿之间的任意值，\u003ccode class=\"command\"\u003eVACUUM\u003c/code\u003e 仍会将实际生效值自动调整为不低于\u003ca href=\"/docs/18/runtime-config-vacuum.html#GUC-AUTOVACUUM-MULTIXACT-FREEZE-MAX-AGE\"\u003eautovacuum_multixact_freeze_max_age\u003c/a\u003e的 105%。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["14","15","16","17","18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
