codekingpro/portable-devtools
114k
1<?xml version="1.0" encoding="UTF-8" standalone="no"?>2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>E.1. Release 16.3</title><link rel="stylesheet" type="text/css" href="stylesheet.css" /><link rev="made" href="pgsql-docs@lists.postgresql.org" /><meta name="generator" content="DocBook XSL Stylesheets Vsnapshot" /><link rel="prev" href="release.html" title="Appendix E. Release Notes" /><link rel="next" href="release-16-2.html" title="E.2. Release 16.2" /></head><body id="docContent" class="container-fluid col-10"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="5" align="center">E.1. Release 16.3</th></tr><tr><td width="10%" align="left"><a accesskey="p" href="release.html" title="Appendix E. Release Notes">Prev</a> </td><td width="10%" align="left"><a accesskey="u" href="release.html" title="Appendix E. Release Notes">Up</a></td><th width="60%" align="center">Appendix E. Release Notes</th><td width="10%" align="right"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="10%" align="right"> <a accesskey="n" href="release-16-2.html" title="E.2. Release 16.2">Next</a></td></tr></table><hr /></div><div class="sect1" id="RELEASE-16-3"><div class="titlepage"><div><div><h2 class="title" style="clear: both">E.1. Release 16.3 <a href="#RELEASE-16-3" class="id_link">#</a></h2></div></div></div><div class="toc"><dl class="toc"><dt><span class="sect2"><a href="release-16-3.html#RELEASE-16-3-MIGRATION">E.1.1. Migration to Version 16.3</a></span></dt><dt><span class="sect2"><a href="release-16-3.html#RELEASE-16-3-CHANGES">E.1.2. Changes</a></span></dt></dl></div><p><strong>Release date: </strong>2024-05-09</p><p>3 This release contains a variety of fixes from 16.2.4 For information about new features in major release 16, see5 <a class="xref" href="release-16.html" title="E.4. Release 16">Section E.4</a>.6 </p><div class="sect2" id="RELEASE-16-3-MIGRATION"><div class="titlepage"><div><div><h3 class="title">E.1.1. Migration to Version 16.3 <a href="#RELEASE-16-3-MIGRATION" class="id_link">#</a></h3></div></div></div><p>7 A dump/restore is not required for those running 16.X.8 </p><p>9 However, a security vulnerability was found in the system10 views <code class="structname">pg_stats_ext</code>11 and <code class="structname">pg_stats_ext_exprs</code>, potentially allowing12 authenticated database users to see data they shouldn't. If this is13 of concern in your installation, follow the steps in the first14 changelog entry below to rectify it.15 </p><p>16 Also, if you are upgrading from a version earlier than 16.2,17 see <a class="xref" href="release-16-2.html" title="E.2. Release 16.2">Section E.2</a>.18 </p></div><div class="sect2" id="RELEASE-16-3-CHANGES"><div class="titlepage"><div><div><h3 class="title">E.1.2. Changes <a href="#RELEASE-16-3-CHANGES" class="id_link">#</a></h3></div></div></div><div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem"><p>19 Restrict visibility of <code class="structname">pg_stats_ext</code> and20 <code class="structname">pg_stats_ext_exprs</code> entries to the table21 owner (Nathan Bossart)22 </p><p>23 These views failed to hide statistics for expressions that involve24 columns the accessing user does not have permission to read. View25 columns such as <code class="structfield">most_common_vals</code> might26 expose security-relevant data. The potential interactions here are27 not fully clear, so in the interest of erring on the side of safety,28 make rows in these views visible only to the owner of the associated29 table.30 </p><p>31 The <span class="productname">PostgreSQL</span> Project thanks32 Lukas Fittl for reporting this problem.33 (CVE-2024-4317)34 </p><p>35 By itself, this fix will only fix the behavior in newly initdb'd36 database clusters. If you wish to apply this change in an existing37 cluster, you will need to do the following:38 </p><div class="procedure"><ol class="procedure" type="1"><li class="step"><p>39 Find the SQL script <code class="filename">fix-CVE-2024-4317.sql</code> in40 the <em class="replaceable"><code>share</code></em> directory of41 the <span class="productname">PostgreSQL</span> installation (typically42 located someplace like <code class="filename">/usr/share/postgresql/</code>).43 Be sure to use the script appropriate to44 your <span class="productname">PostgreSQL</span> major version.45 If you do not see this file, either your version is not vulnerable46 (only v14–v16 are affected) or your minor version is too47 old to have the fix.48 </p></li><li class="step"><p>49 In <span class="emphasis"><em>each</em></span> database of the cluster, run50 the <code class="filename">fix-CVE-2024-4317.sql</code> script as superuser.51 In <span class="application">psql</span> this would look like52</p><pre class="programlisting">53\i /usr/share/postgresql/fix-CVE-2024-4317.sql54</pre><p>55 (adjust the file path as appropriate). Any error probably indicates56 that you've used the wrong script version. It will not hurt to run57 the script more than once.58 </p></li><li class="step"><p>59 Do not forget to include the <code class="literal">template0</code>60 and <code class="literal">template1</code> databases, or the vulnerability61 will still exist in databases you create later. To62 fix <code class="literal">template0</code>, you'll need to temporarily make63 it accept connections. Do that with64</p><pre class="programlisting">65ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true;66</pre><p>67 and then after fixing <code class="literal">template0</code>, undo it with68</p><pre class="programlisting">69ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false;70</pre><p>71 </p></li></ol></div></li><li class="listitem"><p>72 Fix <code class="command">INSERT</code> from73 multiple <code class="command">VALUES</code> rows into a target column that is74 a domain over an array or composite type (Tom Lane)75 </p><p>76 Such cases would either fail with surprising complaints about77 mismatched datatypes, or insert unexpected coercions that could lead78 to odd results.79 </p></li><li class="listitem"><p>80 Require <code class="literal">SELECT</code> privilege on the target table81 for <code class="command">MERGE</code> with a <code class="literal">DO NOTHING</code>82 clause (Álvaro Herrera)83 </p><p>84 <code class="literal">SELECT</code> privilege would be required in all85 practical cases anyway, but require it even if the query reads no86 columns of the target table. This avoids an edge case in87 which <code class="command">MERGE</code> would require no privileges whatever,88 which seems undesirable even when it's a do-nothing command.89 </p></li><li class="listitem"><p>90 Fix handling of self-modified tuples in <code class="command">MERGE</code>91 (Dean Rasheed)92 </p><p>93 Throw an error if a target row joins to more than one source row, as94 required by the SQL standard. (The previous coding could silently95 ignore this condition if a concurrent update was involved.) Also,96 throw a non-misleading error if a target row is already updated by a97 later command in the current transaction, thanks to98 a <code class="literal">BEFORE</code> trigger or a volatile function used in99 the query.100 </p></li><li class="listitem"><p>101 Fix incorrect pruning of NULL partition when a table is partitioned102 on a boolean column and the query has a boolean <code class="literal">IS103 NOT</code> clause (David Rowley)104 </p><p>105 A NULL value satisfies a clause such106 as <code class="literal"><em class="replaceable"><code>boolcol</code></em> IS NOT107 FALSE</code>, so pruning away a partition containing NULLs108 yielded incorrect answers.109 </p></li><li class="listitem"><p>110 Make <code class="command">ALTER FOREIGN TABLE SET SCHEMA</code> move any111 owned sequences into the new schema (Tom Lane)112 </p><p>113 Moving a regular table to a new schema causes any sequences owned by114 the table to be moved to that schema too (along with indexes and115 constraints). This was overlooked for foreign tables, however.116 </p></li><li class="listitem"><p>117 Make <code class="command">ALTER TABLE ... ADD COLUMN</code> create118 identity/serial sequences with the same persistence as their owning119 tables (Peter Eisentraut)120 </p><p>121 <code class="command">CREATE UNLOGGED TABLE</code> will make any owned122 sequences be unlogged too. <code class="command">ALTER TABLE</code> missed123 that consideration, so that an added identity column would have a124 logged sequence, which seems pointless.125 </p></li><li class="listitem"><p>126 Improve <code class="command">ALTER TABLE ... ALTER COLUMN TYPE</code>'s error127 message when there is a dependent function or publication (Tom Lane)128 </p></li><li class="listitem"><p>129 In <code class="command">CREATE DATABASE</code>, recognize strategy keywords130 case-insensitively for consistency with other options (Tomas Vondra)131 </p></li><li class="listitem"><p>132 Fix <code class="command">EXPLAIN</code>'s counting of heap pages accessed by133 a bitmap heap scan (Melanie Plageman)134 </p><p>135 Previously, heap pages that contain no visible tuples were not136 counted; but it seems more consistent to count all pages returned by137 the bitmap index scan.138 </p></li><li class="listitem"><p>139 Fix <code class="command">EXPLAIN</code>'s output for subplans140 in <code class="command">MERGE</code> (Dean Rasheed)141 </p><p>142 <code class="command">EXPLAIN</code> would sometimes fail to properly display143 subplan Params referencing variables in other parts of the plan tree.144 </p></li><li class="listitem"><p>145 Avoid deadlock during removal of orphaned temporary tables146 (Mikhail Zhilin)147 </p><p>148 If the session that creates a temporary table crashes without149 removing the table, autovacuum will eventually try to remove the150 orphaned table. However, an incoming session that's been assigned151 the same temporary namespace will do that too. If a temporary table152 has a dependency (such as an owned sequence) then a deadlock could153 result between these two cleanup attempts.154 </p></li><li class="listitem"><p>155 Fix updating of visibility map state in <code class="command">VACUUM</code>156 with the <code class="literal">DISABLE_PAGE_SKIPPING</code> option (Heikki157 Linnakangas)158 </p><p>159 Due to an oversight, this mode caused all heap pages to be dirtied,160 resulting in excess I/O. Also, visibility map bits that were161 incorrectly set would not get cleared.162 </p></li><li class="listitem"><p>163 Avoid race condition while examining per-relation frozen-XID values164 (Noah Misch)165 </p><p>166 <code class="command">VACUUM</code>'s computation of per-database frozen-XID167 values from per-relation values could get confused by a concurrent168 update of those values by another <code class="command">VACUUM</code>.169 </p></li><li class="listitem"><p>170 Fix buffer usage reporting for parallel vacuuming (Anthonin Bonnefoy)171 </p><p>172 Buffer accesses performed by parallel workers were not getting173 counted in the statistics reported in <code class="literal">VERBOSE</code>174 mode.175 </p></li><li class="listitem"><p>176 Ensure that join conditions generated from equivalence classes are177 applied at the correct plan level (Tom Lane)178 </p><p>179 In versions before <span class="productname">PostgreSQL</span> 16, it was180 possible for generated conditions to be evaluated below outer joins181 when they should be evaluated above (after) the outer join, leading182 to incorrect query results. All versions have a similar hazard when183 considering joins to <code class="command">UNION ALL</code> trees that have184 constant outputs for the join column in185 some <code class="command">SELECT </code> arms.186 </p></li><li class="listitem"><p>187 Fix <span class="quote">“<span class="quote">could not find pathkey item to sort</span>”</span> errors188 occurring while planning aggregate functions with <code class="literal">ORDER189 BY</code> or <code class="literal">DISTINCT</code> options (David Rowley)190 </p><p>191 This is similar to a fix applied in 16.1, but it solves the problem192 for parallel plans.193 </p></li><li class="listitem"><p>194 Prevent potentially-incorrect optimization of some window functions195 (David Rowley)196 </p><p>197 Disable <span class="quote">“<span class="quote">run condition</span>”</span> optimization198 of <code class="function">ntile()</code> and <code class="function">count()</code>199 with non-constant arguments. This avoids possible misbehavior with200 sub-selects, typically leading to errors like <span class="quote">“<span class="quote">WindowFunc not201 found in subplan target lists</span>”</span>.202 </p></li><li class="listitem"><p>203 Avoid unnecessary use of moving-aggregate mode with a non-moving204 window frame (Vallimaharajan G)205 </p><p>206 When a plain aggregate is used as a window function, and the window207 frame start is specified as <code class="literal">UNBOUNDED PRECEDING</code>,208 the frame's head cannot move so we do not need to use the special209 (and more expensive) moving-aggregate mode. This optimization was210 intended all along, but due to a coding error it never triggered.211 </p></li><li class="listitem"><p>212 Avoid use of already-freed data while planning partition-wise joins213 under GEQO (Tom Lane)214 </p><p>215 This would typically end in a crash or unexpected error message.216 </p></li><li class="listitem"><p>217 Avoid freeing still-in-use data in Memoize (Tender Wang, Andrei218 Lepikhov)219 </p><p>220 In production builds this error frequently didn't cause any221 problems, as the freed data would most likely not get overwritten222 before it was used.223 </p></li><li class="listitem"><p>224 Fix incorrectly-reported statistics kind codes in <span class="quote">“<span class="quote">requested225 statistics kind <em class="replaceable"><code>X</code></em> is not yet226 built</span>”</span> error messages (David Rowley)227 </p></li><li class="listitem"><p>228 Use a hash table instead of linear search for <span class="quote">“<span class="quote">catcache229 list</span>”</span> objects (Tom Lane)230 </p><p>231 This change solves performance problems that were reported for232 certain operations in installations with many thousands of roles.233 </p></li><li class="listitem"><p>234 Be more careful with <code class="type">RECORD</code>-returning functions235 in <code class="literal">FROM</code> (Tom Lane)236 </p><p>237 The output columns of such a function call must be defined by238 an <code class="literal">AS</code> clause that specifies the column names and239 data types. If the actual function output value doesn't match that,240 an error is supposed to be thrown at runtime. However, some code241 paths would examine the actual value prematurely, and potentially242 issue strange errors or suffer assertion failures if it doesn't243 match expectations.244 </p></li><li class="listitem"><p>245 Fix confusion about the return rowtype of SQL-language procedures246 (Tom Lane)247 </p><p>248 A procedure implemented in SQL language that returns a single249 composite-type column would cause an assertion failure or core dump.250 </p></li><li class="listitem"><p>251 Add protective stack depth checks to some recursive functions252 (Egor Chindyaskin)253 </p></li><li class="listitem"><p>254 Fix mis-rounding and overflow hazards255 in <code class="function">date_bin()</code> (Moaaz Assali)256 </p><p>257 In the case where the source timestamp is before the origin258 timestamp and their difference is already an exact multiple of the259 stride, the code incorrectly subtracted the stride anyway. Also,260 detect some integer-overflow cases that would have produced261 incorrect results.262 </p></li><li class="listitem"><p>263 Detect integer overflow when adding or subtracting264 an <code class="type">interval</code> to/from a <code class="type">timestamp</code>265 (Joseph Koshakow)266 </p><p>267 Some cases that should cause an out-of-range error produced an268 incorrect result instead.269 </p></li><li class="listitem"><p>270 Avoid race condition in <code class="function">pg_get_expr()</code>271 (Tom Lane)272 </p><p>273 If the relation referenced by the argument is dropped concurrently,274 the function's intention is to return NULL, but sometimes it failed275 instead.276 </p></li><li class="listitem"><p>277 Fix detection of old transaction IDs in XID status functions278 (Karina Litskevich)279 </p><p>280 Transaction IDs more than 2<sup>31</sup>281 transactions in the past could be misidentified as recent,282 leading to misbehavior of <code class="function">pg_xact_status()</code>283 or <code class="function">txid_status()</code>.284 </p></li><li class="listitem"><p>285 Ensure that a table's freespace map won't return a page that's past286 the end of the table (Ronan Dunklau)287 </p><p>288 Because the freespace map isn't WAL-logged, this was possible in289 edge cases involving an OS crash, a replica promote, or a PITR290 restore. The result would be a <span class="quote">“<span class="quote">could not read block</span>”</span>291 error.292 </p></li><li class="listitem"><p>293 Fix file descriptor leakage when an error is thrown while waiting294 in <code class="function">WaitEventSetWait</code> (Etsuro Fujita)295 </p></li><li class="listitem"><p>296 Avoid corrupting exception stack if an FDW implements async append297 but doesn't configure any wait conditions for the Append plan node298 to wait for (Alexander Pyhalov)299 </p></li><li class="listitem"><p>300 Throw an error if an index is accessed while it is being reindexed301 (Tom Lane)302 </p><p>303 Previously this was just an assertion check, but promote it into a304 regular runtime error. This will provide a more on-point error305 message when reindexing a user-defined index expression that306 attempts to access its own table.307 </p></li><li class="listitem"><p>308 Ensure that index-only scans on <code class="type">name</code> columns return a309 fully-padded value (David Rowley)310 </p><p>311 The value physically stored in the index is truncated, and312 previously a pointer to that value was returned to callers. This313 provoked complaints when testing under valgrind. In theory it could314 result in crashes, though none have been reported.315 </p></li><li class="listitem"><p>316 Fix race condition that could lead to reporting an incorrect317 conflict cause when invalidating a replication slot (Bertrand318 Drouvot)319 </p></li><li class="listitem"><p>320 Fix race condition in deciding whether a table sync operation is321 needed in logical replication (Vignesh C)322 </p><p>323 An invalidation event arriving while a subscriber identifies which324 tables need to be synced would be forgotten about, so that any325 tables newly in need of syncing might not get processed in a timely326 fashion.327 </p></li><li class="listitem"><p>328 Fix crash with DSM allocations larger than 4GB (Heikki Linnakangas)329 </p></li><li class="listitem"><p>330 Disconnect if a new server session's client socket cannot be put331 into non-blocking mode (Heikki Linnakangas)332 </p><p>333 It was once theoretically possible for us to operate with a socket334 that's in blocking mode; but that hasn't worked fully in a long335 time, so fail at connection start rather than misbehave later.336 </p></li><li class="listitem"><p>337 Fix inadequate error reporting338 with <span class="application">OpenSSL</span> 3.0.0 and later (Heikki339 Linnakangas, Tom Lane)340 </p><p>341 System-reported errors passed through by OpenSSL were reported with342 a numeric error code rather than anything readable.343 </p></li><li class="listitem"><p>344 Fix thread-safety of error reporting345 for <code class="function">getaddrinfo()</code> on Windows (Thomas Munro)346 </p><p>347 A multi-threaded <span class="application">libpq</span> client program348 could get an incorrect or corrupted error message after a network349 lookup failure.350 </p></li><li class="listitem"><p>351 Avoid concurrent calls to <code class="function">bindtextdomain()</code>352 in <span class="application">libpq</span>353 and <span class="application">ecpglib</span> (Tom Lane)354 </p><p>355 Although GNU <span class="application">gettext</span>'s implementation356 seems to be fine with concurrent calls, the version available on357 Windows is not.358 </p></li><li class="listitem"><p>359 Fix crash in <span class="application">ecpg</span>'s preprocessor if360 the program tries to redefine a macro that was defined on the361 preprocessor command line (Tom Lane)362 </p></li><li class="listitem"><p>363 In <span class="application">ecpg</span>, avoid issuing364 false <span class="quote">“<span class="quote">unsupported feature will be passed to server</span>”</span>365 warnings (Tom Lane)366 </p></li><li class="listitem"><p>367 Ensure that the string result368 of <span class="application">ecpg</span>'s <code class="function">intoasc()</code>369 function is correctly zero-terminated (Oleg Tselebrovskiy)370 </p></li><li class="listitem"><p>371 In <span class="application">initdb</span>'s <code class="option">-c</code> option,372 match parameter names case-insensitively (Tom Lane)373 </p><p>374 The server treats parameter names case-insensitively, so this code375 should too. This avoids putting redundant entries into the376 generated <code class="filename">postgresql.conf</code> file.377 </p></li><li class="listitem"><p>378 In <span class="application">psql</span>, avoid leaking a query result379 after the query is cancelled (Tom Lane)380 </p><p>381 This happened only when cancelling a non-last query in a query382 string made with <code class="literal">\;</code> separators.383 </p></li><li class="listitem"><p>384 Fix <span class="application">pg_dumpall</span> so that role comments, if385 present, will be dumped regardless of the setting386 of <code class="option">--no-role-passwords</code> (Daniel Gustafsson,387 Álvaro Herrera)388 </p></li><li class="listitem"><p>389 Skip files named <code class="filename">.DS_Store</code>390 in <span class="application">pg_basebackup</span>,391 <span class="application">pg_checksums</span>,392 and <span class="application">pg_rewind</span> (Daniel Gustafsson)393 </p><p>394 This avoids problems on macOS, where the Finder may create such395 files.396 </p></li><li class="listitem"><p>397 Fix <span class="application">PL/pgSQL</span>'s parsing of single-line398 comments (<code class="literal">--</code>-style comments) following399 expressions (Erik Wienhold, Tom Lane)400 </p><p>401 This mistake caused parse errors if such a comment followed402 a <code class="literal">WHEN</code> expression in403 a <span class="application">PL/pgSQL</span> <code class="command">CASE</code>404 statement.405 </p></li><li class="listitem"><p>406 In <code class="filename">contrib/amcheck</code>, don't report false match407 failures due to short- versus long-header values (Andrey Borodin,408 Michael Zhilin)409 </p><p>410 A variable-length datum in a heap tuple or index tuple could have411 either a short or a long header, depending on compression parameters412 that applied when it was made. Treat these cases as equivalent413 rather than complaining if there's a difference.414 </p></li><li class="listitem"><p>415 Fix bugs in BRIN output functions (Tomas Vondra)416 </p><p>417 These output functions are only used for displaying index entries418 in <code class="filename">contrib/pageinspect</code>, so the errors are of419 limited practical concern.420 </p></li><li class="listitem"><p>421 In <code class="filename">contrib/postgres_fdw</code>, avoid emitting422 requests to sort by a constant (David Rowley)423 </p><p>424 This could occur in cases involving <code class="literal">UNION ALL</code>425 with constant-emitting subqueries. Sorting by a constant is useless426 of course, but it also risks being misinterpreted by the remote427 server, leading to <span class="quote">“<span class="quote">ORDER BY428 position <em class="replaceable"><code>N</code></em> is not in select list</span>”</span>429 errors.430 </p></li><li class="listitem"><p>431 Make <code class="filename">contrib/postgres_fdw</code> set the remote432 session's time zone to <code class="literal">GMT</code>433 not <code class="literal">UTC</code> (Tom Lane)434 </p><p>435 This should have the same results for practical purposes.436 However, <code class="literal">GMT</code> is recognized by hard-wired code in437 the server, while <code class="literal">UTC</code> is looked up in the438 timezone database. So the old code could fail in the unlikely event439 that the remote server's timezone database is missing entries.440 </p></li><li class="listitem"><p>441 In <code class="filename">contrib/xml2</code>, avoid use of library functions442 that have been deprecated in recent versions443 of <span class="application">libxml2</span> (Dmitry Koval)444 </p></li><li class="listitem"><p>445 Fix incompatibility with LLVM 18 (Thomas Munro, Dmitry Dolgov)446 </p></li><li class="listitem"><p>447 Allow <code class="literal">make check</code> to work with448 the <span class="application">musl</span> C library (Thomas Munro, Bruce449 Momjian, Tom Lane)450 </p></li></ul></div></div></div><div class="navfooter"><hr /><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="release.html" title="Appendix E. Release Notes">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="release.html" title="Appendix E. Release Notes">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="release-16-2.html" title="E.2. Release 16.2">Next</a></td></tr><tr><td width="40%" align="left" valign="top">Appendix E. Release Notes </td><td width="20%" align="center"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="40%" align="right" valign="top"> E.2. Release 16.2</td></tr></table></div></body></html>