{"Entry":{"collection":"guc","key":"zero_damaged_pages","name":"zero_damaged_pages","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Developer Options","category_zh":"","changed_in":["17"],"changes":[{"documentation_changed":true,"fields":{},"from":"7.4","status":"changed","to":"8.0"},{"documentation_changed":true,"fields":{},"from":"8.0","status":"changed","to":"8.1"},{"documentation_changed":true,"fields":{},"from":"8.2","status":"changed","to":"8.3"},{"documentation_changed":true,"fields":{},"from":"8.4","status":"changed","to":"9.0"},{"documentation_changed":true,"fields":{},"from":"9.0","status":"changed","to":"9.1"},{"documentation_changed":true,"fields":{},"from":"14","status":"changed","to":"15"},{"documentation_changed":false,"fields":{"extra_desc":{"from":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting zero_damaged_pages to true causes the system to instead report a warning, zero out the damaged page, and continue processing. This behavior will destroy data, namely all the rows on the damaged page.","to":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting \"zero_damaged_pages\" to true causes the system to instead report a warning, zero out the damaged page, and continue processing. This behavior will destroy data, namely all the rows on the damaged page."}},"from":"16","status":"changed","to":"17"}],"content_hash":"f056a9027b68da7b3134b207dac04a674fd1231c2145308ab3358aabf8600e19","context":"","default_changed_in":[],"default_history":[{"from":"9.0","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Read-only analytics does not make zero_damaged_pages safe: corrupted pages can still poison results or structures. Use only on a disposable salvage copy with explicit acceptance of lost data.","oltp":"Never use zero_damaged_pages as tuning or a steady-state availability setting. Stop writes, preserve immutable copies, exhaust backup/storage repair, document expected data loss, salvage narrowly, rebuild, and validate before any return to service.","small":"Do not enable zero_damaged_pages merely because no replica exists. Preserve the original first and seek a clean backup; this switch can convert visible corruption into silent loss."},"mechanism":["When PostgreSQL detects a damaged page header, zero_damaged_pages substitutes an all-zero page in memory, emits a warning, and continues. Every row formerly on that page is thereby lost to the salvage read.","The zero page is not forced to disk automatically, so continuing to use the relation can produce inconsistent behavior. The table or index must be rebuilt after salvage.","This is a last-resort data-extraction switch after backups and storage recovery are exhausted. It must be used on a preserved copy, scoped narrowly, and turned off immediately afterward. Its superuser context permits an authorized session change without a server restart."],"pitfalls":["Leaving zero_damaged_pages enabled after the bounded diagnostic or recovery task.","Running the experiment on the only copy of production data.","Underestimating log, core-file, temporary-file, WAL, CPU, or connection-slot amplification.","Treating a server that merely starts or completes a query as proof that data and behavior are correct."],"references":[{"title":"PostgreSQL 19 Beta 4: zero_damaged_pages","url":"https://www.postgresql.org/docs/19/runtime-config-developer.html#GUC-ZERO-DAMAGED-PAGES"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ignore_checksum_failure","ignore_invalid_pages","data_checksums","wal_consistency_checking"],"summary":"zero_damaged_pages — Continues processing past damaged page headers. Observed in PG9.0–19 Beta 4; its last measured boot default is off in PG19 Beta 4, with superuser context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"7.4","group":"Developer Options","group_slug":"developer","imported_at":"2026-09-27T17:57:32.400915+08:00","intro_commit":{},"key":"zero_damaged_pages","last_version":"20","max_val":"","min_val":"","name":"zero_damaged_pages","position":490,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction.","short_desc_zh":"","source_rev":"english-manuals:00978e5f0ad5e1dfa090fafdc5a1393b500c15e4440783b52c10a96322127b02","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"zero_damaged_pages","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"zero_damaged_pages","SourceRevision":"english-manuals:00978e5f0ad5e1dfa090fafdc5a1393b500c15e4440783b52c10a96322127b02","Facts":{"boot_val":"off","category":"Developer Options","context":"superuser","description":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting zero_damaged_pages to on causes the system to instead report a warning, zero out the damaged page in memory, and continue processing. This behavior will destroy data, namely all the rows on the damaged page. However, it does allow you to get past the error and retrieve rows from any undamaged pages that might be present in the table. It is useful for recovering data if corruption has occurred due to a hardware or software error. You should generally not set this on until you have given up hope of recovering data from the damaged pages of a table. Zeroed-out pages are not forced to disk so it is recommended to recreate the table or the index before turning this parameter off again. The default setting is off. Only superusers and users with the appropriate SET privilege can change this setting.","doc":{"anchor":"GUC-ZERO-DAMAGED-PAGES","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting \"zero_damaged_pages\" to true causes the system to instead report a warning, zero out the damaged page, and continue processing. This behavior will destroy data, namely all the rows on the damaged page.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"zero_damaged_pages","short_desc":"Continues processing past damaged page headers.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-ZERO-DAMAGED-PAGES","file":"runtime-config-developer.html","lang":"en","sha256":"f5e7e39d176c642ac0799c87669ce2f6f60fcd97d109e290860ec74c36d7ecad","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"zero_damaged_pages","SourceDatabase":"center","Version":"18","Locale":"en","Title":"zero_damaged_pages","Summary":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting zero_damaged_pages to on causes the system to instead report a warning, zero out the damaged page in memory, and continue processing. This behavior will destroy data, namely all the rows on the damaged page. However, it does allow you to get past the error and retrieve rows from any undamaged pages that might be present in the table. It is useful for recovering data if corruption has occurred due to a hardware or software error. You should generally not set this on until you have given up hope of recovering data from the damaged pages of a table. Zeroed-out pages are not forced to disk so it is recommended to recreate the table or the index before turning this parameter off again. The default setting is off. Only superusers and users with the appropriate SET privilege can change this setting.","BodyHTML":"\u003cp\u003eDetection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting zero_damaged_pages to on causes the system to instead report a warning, zero out the damaged page in memory, and continue processing. This behavior will destroy data, namely all the rows on the damaged page. However, it does allow you to get past the error and retrieve rows from any undamaged pages that might be present in the table. It is useful for recovering data if corruption has occurred due to a hardware or software error. You should generally not set this on until you have given up hope of recovering data from the damaged pages of a table. Zeroed-out pages are not forced to disk so it is recommended to recreate the table or the index before turning this parameter off again. The default setting is off. Only superusers and users with the appropriate SET privilege can change this setting.\u003c/p\u003e","SourceRevision":"english-manuals:00978e5f0ad5e1dfa090fafdc5a1393b500c15e4440783b52c10a96322127b02","ContentHash":"c8e5469538225e1f0a25de2093e281ef17c10262b93550941bcecf76ecfa1e3e","Payload":{"description":"Detection of a damaged page header normally causes PostgreSQL to report an error, aborting the current transaction. Setting zero_damaged_pages to on causes the system to instead report a warning, zero out the damaged page in memory, and continue processing. This behavior will destroy data, namely all the rows on the damaged page. However, it does allow you to get past the error and retrieve rows from any undamaged pages that might be present in the table. It is useful for recovering data if corruption has occurred due to a hardware or software error. You should generally not set this on until you have given up hope of recovering data from the damaged pages of a table. Zeroed-out pages are not forced to disk so it is recommended to recreate the table or the index before turning this parameter off again. The default setting is off. Only superusers and users with the appropriate SET privilege can change this setting."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
