{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2010-10-04", "build": "9.0.1", "major": "9.0", "minor": 1, "manual": "9.0", "status": "stable", "doc_git": "", "version": "9.0.1", "eol_date": "2015-10-08", "date_text": "2010-10-04", "supported": false, "manual_url": "/docs/9.0/release-9-0-1.html", "source_url": "/docs/release/9.0.1/", "entry_count": 10, "placeholder": false, "content_hash": "40592d3b9a2dd0a6d0c5822da476cb34374da5f3c194124acfd6ff4b052a363b", "manual_build": "9.0.23", "source_as_of": "", "changes_count": 10, "doc_loaded_at": "2026-09-26T02:56:48.570247", "migration_html": "<p>对于运行 9.0.X 的用户，不需要进行转储/恢复。</p>", "compatibility_count": 0, "label": "9.0.1", "status_label": "历史版本", "eol": "2015-10-08", "age_days": 5840, "support_days": -4010}, "groups": [{"date": "2010-10-04", "build": "9.0.1", "major": "9.0", "minor": 1, "manual": "9.0", "status": "stable", "doc_git": "", "version": "9.0.1", "eol_date": "2015-10-08", "date_text": "2010-10-04", "supported": false, "manual_url": "/docs/9.0/release-9-0-1.html", "source_url": "/docs/release/9.0.1/", "entry_count": 10, "placeholder": false, "content_hash": "40592d3b9a2dd0a6d0c5822da476cb34374da5f3c194124acfd6ff4b052a363b", "manual_build": "9.0.23", "source_as_of": "", "changes_count": 10, "doc_loaded_at": "2026-09-26T02:56:48.570247", "migration_html": "<p>对于运行 9.0.X 的用户，不需要进行转储/恢复。</p>", "compatibility_count": 0, "label": "9.0.1", "status_label": "历史版本", "eol": "2015-10-08", "age_days": 5840, "support_days": -4010, "entries": [{"id": "9.0.1-c624c8adcc0176f4", "cves": ["CVE-2010-3433"], "html": "<p>在 PL/Perl 和 PL/Tcl 中为每个调用方 SQL 用户 ID 使用单独的解释器（Tom Lane）</p>\n<p>此变更防止了可通过破坏稍后将在同一会话中以另一 SQL 用户身份执行的 Perl 或 Tcl 代码（例如在 <code>SECURITY DEFINER</code> 函数内）而造成的安全问题。大多数脚本语言都提供许多实现这一点的手段，例如重新定义目标函数调用的标准函数或操作符。如果没有此变更，任何拥有 Perl 或 Tcl 语言使用权的 SQL 用户基本上都能以目标函数所有者的 SQL 权限为所欲为。</p>\n<p>此变更的代价是 Perl 和 Tcl 函数之间的有意通信变得更困难。为提供出路，PL/PerlU 和 PL/TclU 函数继续每会话只使用一个解释器。这不被视为安全问题，因为所有这类函数本来就以数据库超级用户的信任级别执行。</p>\n<p>声称提供可信执行的第三方过程语言很可能存在类似的安全问题。我们建议就安全关键用途联系你所依赖的任何 PL 的作者。</p>\n<p>感谢 Tim Bunce 指出此问题（CVE-2010-3433）。</p>", "text": "在 PL/Perl 和 PL/Tcl 中为每个调用方 SQL 用户 ID 使用单独的解释器（Tom Lane） 此变更防止了可通过破坏稍后将在同一会话中以另一 SQL 用户身份执行的 Perl 或 Tcl 代码（例如在 SECURITY DEFINER 函数内）而造成的安全问题。大多数脚本语言都提供许多实现这一点的手段，例如重新定义目标函数调用的标准函数或操作符。如果没有此变更，任何拥有 Perl 或 Tcl 语言使用权的 SQL 用户基本上都能以目标函数所有者的 SQL 权限为所欲为。 此变更的代价是 Perl 和 Tcl 函数之间的有意通信变得更困难。为提供出路，PL/PerlU 和 PL/TclU 函数继续每会话只使用一个解释器。这不被视为安全问题，因为所有这类函数本来就以数据库超级用户的信任级别执行。 声称提供可信执行的第三方过程语言很可能存在类似的安全问题。我们建议就安全关键用途联系你所依赖的任何 PL 的作者。 感谢 Tim Bunce 指出此问题（CVE-2010-3433）。", "title": "在 PL/Perl 和 PL/Tcl 中为每个调用方 SQL 用户 ID 使用单独的解释器", "commits": [], "section": "变更", "category": "security", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "7595824ebbb771e36673953a0db338fda17be64a87018d5567b2c9c28387482d", "section_path": ["变更"], "commit_groups": [], "identity_text": "Use a separate interpreter for each calling SQL userid in PL/Perl and PL/Tcl (Tom Lane) This change prevents security problems that can be caused by subverting Perl or Tcl code that will be executed later in the same session under another SQL user identity (for example, within a SECURITY DEFINER function). Most scripting languages offer numerous ways that that might be done, such as redefining standard functions or operators called by the target function. Without this change, any SQL user with Perl or Tcl language usage rights can do essentially anything with the SQL privileges of the target function's owner. The cost of this change is that intentional communication among Perl and Tcl functions becomes more difficult. To provide an escape hatch, PL/PerlU and PL/TclU functions continue to use only one interpreter per session. This is not considered a security issue since all such functions execute at the trust level of a database superuser already. It is likely that third-party procedural languages that claim to offer trusted execution have similar security issues. We advise contacting the authors of any PL you are depending on for security-critical purposes. Our thanks to Tim Bunce for pointing out this issue (CVE-2010-3433).", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/001", "db_id": "491239023374ba84bfc8e1efde211029", "patch_ids": [], "statement_hash": "919e1d60dbdb889b71827b41def2c79179825514e699d86c55bea11808fa1c5d", "relations": [], "version": "9.0.1", "category_label": "安全相关", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-fa8a98adde2e4c45", "cves": [], "html": "<p>改进 <code>pg_get_expr()</code> 的安全修复，使该函数仍可用于子 SELECT 的输出（Tom Lane）</p>", "text": "改进 pg_get_expr() 的安全修复，使该函数仍可用于子 SELECT 的输出（Tom Lane）", "title": "改进 pg_get_expr() 的安全修复，使该函数仍可用于子 SELECT 的输出", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "22cb4661228d3df6b973975525feb783754146d8f8a154f5de48a1d464a40bee", "section_path": ["变更"], "commit_groups": [], "identity_text": "Improve pg_get_expr() security fix so that the function can still be used on the output of a sub-select (Tom Lane)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/002", "db_id": "d31119b7a615a4cf53b9bb064bdf4bfd", "patch_ids": [], "statement_hash": "41ea78ee317bc5d40d2aa100d873c4e2b79246a7c43d295428226c2cc3c96037", "relations": [], "version": "9.0.1", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-23da127fd07b1a59", "cves": [], "html": "<p>修复占位符求值位置不正确的问题（Tom Lane）</p>\n<p>当外连接的内侧是输出列表中含非严格表达式的子 SELECT 时，该缺陷可能导致本应为空的查询输出非空。</p>", "text": "修复占位符求值位置不正确的问题（Tom Lane） 当外连接的内侧是输出列表中含非严格表达式的子 SELECT 时，该缺陷可能导致本应为空的查询输出非空。", "title": "修复占位符求值位置不正确的问题", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "c0eff0953d2564e017a5aa451218b1844b8c861cbb57a414dafe03f939abc637", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix incorrect placement of placeholder evaluation (Tom Lane) This bug could result in query outputs being non-null when they should be null, in cases where the inner side of an outer join is a sub-select with non-strict expressions in its output list.", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/003", "db_id": "58a1999e525004e1437506f26464bb19", "patch_ids": [], "statement_hash": "d57a66324d30476e4815ea1fd5f383be27872fe2a82fcfe0502f31db84be3a41", "relations": [], "version": "9.0.1", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-c0c377a05122b9d0", "cves": [], "html": "<p>修复连接消除对占位符表达式的处理（Tom Lane）</p>", "text": "修复连接消除对占位符表达式的处理（Tom Lane）", "title": "修复连接消除对占位符表达式的处理", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "012ef97029f0e54a63ab77efbe3262eb7be9fd3e821afefce3e4b176f8740301", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix join removal's handling of placeholder expressions (Tom Lane)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/004", "db_id": "237740152fb17773601a84c6ac3f8fd8", "patch_ids": [], "statement_hash": "664d90c5653bfbd7ab67495b2e3a610089b5b5a4e25cb92b547a65752625ccb7", "relations": [], "version": "9.0.1", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-b28b3107c02a7a25", "cves": [], "html": "<p>修复 <code>UNION ALL</code> 成员关系可能被重复扫描的问题（Tom Lane）</p>", "text": "修复 UNION ALL 成员关系可能被重复扫描的问题（Tom Lane）", "title": "修复 UNION ALL 成员关系可能被重复扫描的问题", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "6009f7448fc47d91af550d657a68a43d62da3ba42de6db4d65b9621341bbcb2c", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix possible duplicate scans of UNION ALL member relations (Tom Lane)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/005", "db_id": "fe0acc2a49e5d713012f383f3d8804c9", "patch_ids": [], "statement_hash": "4874e84641167897f2a8770c1ecb9207e0b47d4a34ca3f1be4bf595dc246a5da", "relations": [], "version": "9.0.1", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-47b0130542946504", "cves": [], "html": "<p>防止取消监听后 ProcessIncomingNotify() 中的无限循环（Jeff Davis）</p>", "text": "防止取消监听后 ProcessIncomingNotify() 中的无限循环（Jeff Davis）", "title": "防止取消监听后 ProcessIncomingNotify() 中的无限循环", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "97e89b7695cf331c005a36796e78db59468be8843b8ab57538b340ebe35d1194", "section_path": ["变更"], "commit_groups": [], "identity_text": "Prevent infinite loop in ProcessIncomingNotify() after unlistening (Jeff Davis)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/006", "db_id": "e25739c5024af137c583a5c56f764b66", "patch_ids": [], "statement_hash": "7fc1dd7cdb189a06b5ed0a4b6bed825bdd44800bd43f13c1bcfb49081c2e657d", "relations": [], "version": "9.0.1", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-0d2918f16a552ab7", "cves": [], "html": "<p>防止 show_session_authorization() 在自动清理进程中崩溃（Tom Lane）</p>", "text": "防止 show_session_authorization() 在自动清理进程中崩溃（Tom Lane）", "title": "防止 show_session_authorization() 在自动清理进程中崩溃", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "ad0c543230fee2735fb3f52aafe5fb9be71a2a1f45f586bbb5c9476a0857954c", "section_path": ["变更"], "commit_groups": [], "identity_text": "Prevent show_session_authorization() from crashing within autovacuum processes (Tom Lane)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/007", "db_id": "86f194f707157b9694d05165461d64ef", "patch_ids": [], "statement_hash": "c41fcbe70702d932dd2d6fd21a34c8d213f7a65882d3ce71baff1c9f13307ba2", "relations": [], "version": "9.0.1", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-78fa0a62c4d68365", "cves": [], "html": "<p>重新允许输入公元 0001-01-01 之前的儒略日期（Tom Lane）</p>\n<p>像 <code>'J100000'::date</code> 这样的输入在 8.4 之前可行，但被新增的错误检查无意中破坏。</p>", "text": "重新允许输入公元 0001-01-01 之前的儒略日期（Tom Lane） 像 'J100000'::date 这样的输入在 8.4 之前可行，但被新增的错误检查无意中破坏。", "title": "重新允许输入公元 0001-01-01 之前的儒略日期", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "9f8044cdaeefa8746da7bcc8707d1b7b27fc8f562fec305644e1ae4cc36e8aac", "section_path": ["变更"], "commit_groups": [], "identity_text": "Re-allow input of Julian dates prior to 0001-01-01 AD (Tom Lane) Input such as 'J100000'::date worked before 8.4, but was unintentionally broken by added error-checking.", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/008", "db_id": "21b0d5c3d442260382c49e4f3feb5742", "patch_ids": [], "statement_hash": "ddada525738004ce5cdc4b589e26fb396cbbda814032c95772c78422e00e8dbc", "relations": [], "version": "9.0.1", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-baf8e4f574f795d4", "cves": [], "html": "<p>让 psql 在自动提交关闭模式下把 <code>DISCARD ALL</code> 识别为不应包裹在事务块中的命令（Itagaki Takahiro）</p>", "text": "让 psql 在自动提交关闭模式下把 DISCARD ALL 识别为不应包裹在事务块中的命令（Itagaki Takahiro）", "title": "让 psql 在自动提交关闭模式下把 DISCARD ALL 识别为不应包裹在事务块中的命令", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "9779251eaa4e41136402491983b02f7e6286f5218b55e4e17c9215ad162f27bc", "section_path": ["变更"], "commit_groups": [], "identity_text": "Make psql recognize DISCARD ALL as a command that should not be encased in a transaction block in autocommit-off mode (Itagaki Takahiro)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/009", "db_id": "d518cc1d662a819f55ba5f3df34834ba", "patch_ids": [], "statement_hash": "5d46bc9172a5d5d8c3bc45f446f056bd7f4b27c39fef6986a7d5916667974926", "relations": [], "version": "9.0.1", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": []}, {"id": "9.0.1-f285734efb6ae9a4", "cves": [], "html": "<p>更新构建基础设施和文档，反映源代码仓库从 CVS 迁移到 Git 的变化（Magnus Hagander 等）</p>", "text": "更新构建基础设施和文档，反映源代码仓库从 CVS 迁移到 Git 的变化（Magnus Hagander 等）", "title": "更新构建基础设施和文档，反映源代码仓库从 CVS 迁移到 Git 的变化（Magnus Hagander 等）", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.0.1/#id-1.11.6.27.5", "source_hash": "0183f0b259895c5a5e339b225bbd01e78596e5da611fc6dea4492640395fefff", "section_path": ["变更"], "commit_groups": [], "identity_text": "Update build infrastructure and documentation to reflect the source code repository's move from CVS to Git (Magnus Hagander and others)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.0.1/changes/010", "db_id": "c6aa975c2a788b983e12d6369a3dd2fa", "patch_ids": [], "statement_hash": "e9b1e1e377c1197adf85f5546ac19d2e7a3b3aaf4a67b5d6508aa6b97c1e9ba5", "relations": [], "version": "9.0.1", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": []}]}], "stats": [{"key": "all", "label": "全部变更", "count": 10}, {"key": "feature", "label": "新功能", "count": 0}, {"key": "bugfix", "label": "BUG 修复", "count": 5}, {"key": "security", "label": "安全相关", "count": 1}, {"key": "performance", "label": "性能改进", "count": 0}, {"key": "compatibility", "label": "兼容性变化", "count": 0}, {"key": "improvement", "label": "其他改进", "count": 4}], "total": 10, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2010-3433", "url": "https://www.postgresql.org/support/security/CVE-2010-3433/", "fixed": {"7.4": "7.4.30", "8.0": "8.0.26", "8.1": "8.1.22", "8.2": "8.2.18", "8.3": "8.3.12", "8.4": "8.4.5", "9.0": "9.0.1"}, "score": null, "title": "在 PL/Perl 和 PL/Tcl 中为每个调用方 SQL 用户 ID 使用单独的解释器", "vector": "", "affected": {"7.4": "7.4", "8.0": "8.0", "8.1": "8.1", "8.2": "8.2", "8.3": "8.3", "8.4": "8.4", "9.0": "9.0"}, "component": "", "published": {}, "introduced": {}, "cvss_version": "", "description_en": "", "first_published": null, "fixed_version": "9.0.1"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 10, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}