{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2018-03-01", "build": "9.6.8", "major": "9.6", "minor": 8, "manual": "9.6", "status": "stable", "doc_git": "", "version": "9.6.8", "eol_date": "2021-11-11", "date_text": "2018-03-01", "supported": false, "manual_url": "/docs/9.6/release-9-6-8.html", "source_url": "/docs/release/9.6.8/", "entry_count": 8, "placeholder": false, "content_hash": "c05b363b878e7bdbb40bc7feddcc4575c5d4832f39acab15688afb92d196c19d", "manual_build": "9.6.24", "source_as_of": "", "changes_count": 8, "doc_loaded_at": "2026-09-26T02:56:43.973460", "migration_html": "<p>对于运行 9.6.X 的用户，不需要转储/恢复。</p>\n<p>不过，如果你运行的安装中并非所有用户都相互信任，或者你维护打算在任意场合使用的应用或扩展，强烈建议阅读下面第一条变更日志条目所述的文档更改，并采取适当步骤确保你的安装或代码安全。</p>\n<p>另外，下面第二条变更日志条目所述的更改可能导致索引表达式或物化视图中使用的函数在自动分析期间或从转储重新装载时失败。升级之后，请监控服务器日志中此类问题，并修复受影响的函数。</p>\n<p>另外，如果你是从 9.6.7 之前的版本升级，参见<a href=\"/docs/9.6/release-9-6-7.html\" title=\"E.18. 版本 9.6.7\">第 E.18 节</a>。</p>", "compatibility_count": 0, "label": "9.6.8", "status_label": "历史版本", "eol": "2021-11-11", "age_days": 3135, "support_days": -1784}, "groups": [{"date": "2018-03-01", "build": "9.6.8", "major": "9.6", "minor": 8, "manual": "9.6", "status": "stable", "doc_git": "", "version": "9.6.8", "eol_date": "2021-11-11", "date_text": "2018-03-01", "supported": false, "manual_url": "/docs/9.6/release-9-6-8.html", "source_url": "/docs/release/9.6.8/", "entry_count": 8, "placeholder": false, "content_hash": "c05b363b878e7bdbb40bc7feddcc4575c5d4832f39acab15688afb92d196c19d", "manual_build": "9.6.24", "source_as_of": "", "changes_count": 8, "doc_loaded_at": "2026-09-26T02:56:43.973460", "migration_html": "<p>对于运行 9.6.X 的用户，不需要转储/恢复。</p>\n<p>不过，如果你运行的安装中并非所有用户都相互信任，或者你维护打算在任意场合使用的应用或扩展，强烈建议阅读下面第一条变更日志条目所述的文档更改，并采取适当步骤确保你的安装或代码安全。</p>\n<p>另外，下面第二条变更日志条目所述的更改可能导致索引表达式或物化视图中使用的函数在自动分析期间或从转储重新装载时失败。升级之后，请监控服务器日志中此类问题，并修复受影响的函数。</p>\n<p>另外，如果你是从 9.6.7 之前的版本升级，参见<a href=\"/docs/9.6/release-9-6-7.html\" title=\"E.18. 版本 9.6.7\">第 E.18 节</a>。</p>", "compatibility_count": 0, "label": "9.6.8", "status_label": "历史版本", "eol": "2021-11-11", "age_days": 3135, "support_days": -1784, "entries": [{"id": "9.6.8-15416513126c15d4", "cves": ["CVE-2018-1058"], "html": "<p>记录如何配置安装和应用以防受其他用户依赖 search_path 的特洛伊木马攻击（Noah Misch）</p>\n<p>使用包含任何可被恶意用户写入的模式的 <code>search_path</code> 设置，会使该用户能够截获查询的控制，然后以被攻击用户的权限运行任意 SQL 代码。虽然可以写出能防范此类劫持的查询，但记法上很繁琐，而且很容易遗漏漏洞。因此，我们现在推荐不把任何不受信任模式放入搜索路径的配置。相关文档见<a href=\"/docs/9.6/ddl-schemas.html#DDL-SCHEMAS-PATTERNS\" title=\"5.8.6. 使用方式\">第 5.8.6 节</a>（面向数据库管理员和用户）、<a href=\"/docs/9.6/libpq.html#LIBPQ-CONNECT\" title=\"32.1. 数据库连接控制函数\">第 32.1 节</a>（面向应用作者）、<a href=\"/docs/9.6/extend-extensions.html#EXTEND-EXTENSIONS-SECURITY\" title=\"36.15.5. 扩展的安全注意事项\">第 36.15.5 节</a>（面向扩展作者）和<a href=\"/docs/9.6/sql-createfunction.html\" title=\"CREATE FUNCTION\"><span>CREATE FUNCTION</span></a>（面向 <code>SECURITY DEFINER</code> 函数的作者）。（CVE-2018-1058）</p>", "text": "记录如何配置安装和应用以防受其他用户依赖 search_path 的特洛伊木马攻击（Noah Misch） 使用包含任何可被恶意用户写入的模式的 search_path 设置，会使该用户能够截获查询的控制，然后以被攻击用户的权限运行任意 SQL 代码。虽然可以写出能防范此类劫持的查询，但记法上很繁琐，而且很容易遗漏漏洞。因此，我们现在推荐不把任何不受信任模式放入搜索路径的配置。相关文档见第 5.8.6 节（面向数据库管理员和用户）、第 32.1 节（面向应用作者）、第 36.15.5 节（面向扩展作者）和CREATE FUNCTION（面向 SECURITY DEFINER 函数的作者）。（CVE-2018-1058）", "title": "记录如何配置安装和应用以防受其他用户依赖 search_path 的特洛伊木马攻击", "commits": [], "section": "变更", "category": "security", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "9925e62c258a06c8b35fd1f09e3e5a9f92b343ca5cf11fe2272dd8db08685d9a", "section_path": ["变更"], "commit_groups": [], "identity_text": "Document how to configure installations and applications to guard against search-path-dependent trojan-horse attacks from other users (Noah Misch) Using a search_path setting that includes any schemas writable by a hostile user enables that user to capture control of queries and then run arbitrary SQL code with the permissions of the attacked user. While it is possible to write queries that are proof against such hijacking, it is notationally tedious, and it's very easy to overlook holes. Therefore, we now recommend configurations in which no untrusted schemas appear in one's search path. Relevant documentation appears in ddl-schemas-patterns (for database administrators and users), libpq-connect (for application authors), extend-extensions-security (for extension authors), and sql-createfunction (for authors of SECURITY DEFINER functions). (CVE-2018-1058)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/001", "db_id": "82073b679da941aa72a8287b38619ba8", "patch_ids": [], "statement_hash": "f4eb8c1812403c7fd9294768855535e0d4d524fd0478356fc9a8531e7c291d62", "relations": [{"rule": 2, "type": "equivalent", "target": "5a21500343ad00e5e00f3021b610a0a9", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "f4eb8c1812403c7fd9294768855535e0d4d524fd0478356fc9a8531e7c291d62"}}, {"rule": 2, "type": "equivalent", "target": "f34e722728f91f9ee97653e304b9d28b", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "f4eb8c1812403c7fd9294768855535e0d4d524fd0478356fc9a8531e7c291d62"}}], "version": "9.6.8", "category_label": "安全相关", "also_in": [], "variants": [], "related_changes": [{"db_id": "f34e722728f91f9ee97653e304b9d28b", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "记录如何配置安装和应用程序，以防范其他用户利用搜索路径发起的特洛伊木马攻击", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "f4eb8c1812403c7fd9294768855535e0d4d524fd0478356fc9a8531e7c291d62"}, "url": "/docs/compare/?release=10.3#10.3-12464343c3fa6b9c", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "5a21500343ad00e5e00f3021b610a0a9", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "记录如何配置安装和应用以防受其他用户依赖 search_path 的特洛伊木马攻击", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "f4eb8c1812403c7fd9294768855535e0d4d524fd0478356fc9a8531e7c291d62"}, "url": "/docs/compare/?release=9.5.12#9.5.12-15416513126c15d4", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}]}, {"id": "9.6.8-5f3c119a2c06181a", "cves": ["CVE-2018-1058"], "html": "<p>避免在 <span>pg_dump</span> 和其他客户端程序中使用不安全的 <code>search_path</code> 设置（Noah Misch、Tom Lane）</p>\n<p><span>pg_dump</span>、<span>pg_upgrade</span>、 <span>vacuumdb</span> 等 <span>PostgreSQL</span> 自带的应用本身也容易受到上一条变更日志条目所述劫持的影响；由于这些应用通常由超级用户运行，它们是特别有吸引力的目标。为使它们无论整个安装是否已被加固都安全，修改它们使其 <code>search_path</code> 设置只包含 <code>pg_catalog</code> 模式。自动清理工作者进程现在也同样如此。</p>\n<p>当用户提供的函数被这些程序间接执行时（例如索引表达式中的用户提供函数），更严格的 <code>search_path</code> 可能导致错误，需要通过调整这些用户提供的函数使其不对被调用时的搜索路径做任何假定来更正。这从来都是良好实践，但现在这是正确行为的必要条件。（CVE-2018-1058）</p>", "text": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置（Noah Misch、Tom Lane） pg_dump、pg_upgrade、 vacuumdb 等 PostgreSQL 自带的应用本身也容易受到上一条变更日志条目所述劫持的影响；由于这些应用通常由超级用户运行，它们是特别有吸引力的目标。为使它们无论整个安装是否已被加固都安全，修改它们使其 search_path 设置只包含 pg_catalog 模式。自动清理工作者进程现在也同样如此。 当用户提供的函数被这些程序间接执行时（例如索引表达式中的用户提供函数），更严格的 search_path 可能导致错误，需要通过调整这些用户提供的函数使其不对被调用时的搜索路径做任何假定来更正。这从来都是良好实践，但现在这是正确行为的必要条件。（CVE-2018-1058）", "title": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置", "commits": [], "section": "变更", "category": "security", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "086f485051777cfc5575c2811e9fb97623fa278601d1596f843001425d514504", "section_path": ["变更"], "commit_groups": [], "identity_text": "Avoid use of insecure search_path settings in pg_dump and other client programs (Noah Misch, Tom Lane) pg_dump, pg_upgrade, vacuumdb and other PostgreSQL-provided applications were themselves vulnerable to the type of hijacking described in the previous changelog entry; since these applications are commonly run by superusers, they present particularly attractive targets. To make them secure whether or not the installation as a whole has been secured, modify them to include only the pg_catalog schema in their search_path settings. Autovacuum worker processes now do the same, as well. In cases where user-provided functions are indirectly executed by these programs — for example, user-provided functions in index expressions — the tighter search_path may result in errors, which will need to be corrected by adjusting those user-provided functions to not assume anything about what search path they are invoked under. That has always been good practice, but now it will be necessary for correct behavior. (CVE-2018-1058)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/002", "db_id": "285ab0afa4e4e1bda61cb74e401a85e4", "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6", "relations": [{"rule": 2, "type": "equivalent", "target": "07e7c249ed74636cb7ff30cca14583a2", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}}, {"rule": 2, "type": "equivalent", "target": "2ec2e0c64c523020ee8bff794b7dc5bb", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}}, {"rule": 2, "type": "equivalent", "target": "69e724f77f37ca5335e439d572362f89", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}}, {"rule": 2, "type": "equivalent", "target": "9cdc72dacd8957621666de3bc80f94e9", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}}], "version": "9.6.8", "category_label": "安全相关", "also_in": [], "variants": [], "related_changes": [{"db_id": "9cdc72dacd8957621666de3bc80f94e9", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}, "url": "/docs/compare/?release=10.3#10.3-5f3c119a2c06181a", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "69e724f77f37ca5335e439d572362f89", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}, "url": "/docs/compare/?release=9.5.12#9.5.12-5f3c119a2c06181a", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "2ec2e0c64c523020ee8bff794b7dc5bb", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}, "url": "/docs/compare/?release=9.4.17#9.4.17-5f3c119a2c06181a", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "07e7c249ed74636cb7ff30cca14583a2", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "避免在 pg_dump 和其他客户端程序中使用不安全的 search_path 设置", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eb872ee514bdcc8e5a99cee1edd0ab15630d15a4f9d4dc968f51ce88151958c6"}, "url": "/docs/compare/?release=9.3.22#9.3.22-5f3c119a2c06181a", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-a2a2d10a68caa3ed", "cves": [], "html": "<p>修复子计划中出现 CTE 引用时并发更新重检查的错误行为（Tom Lane）</p>\n<p>如果 CTE（<code>WITH</code> 子句引用）被用于 InitPlan 或 SubPlan，且查询因试图更新或锁定并发更新的行而需要重检查，可能得到错误结果。</p>", "text": "修复子计划中出现 CTE 引用时并发更新重检查的错误行为（Tom Lane） 如果 CTE（WITH 子句引用）被用于 InitPlan 或 SubPlan，且查询因试图更新或锁定并发更新的行而需要重检查，可能得到错误结果。", "title": "修复子计划中出现 CTE 引用时并发更新重检查的错误行为", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "ea87e11868ef81a69cdaf6dfe008350f17f6c533db78ab48522ddccf9f5fd5a5", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix misbehavior of concurrent-update rechecks with CTE references appearing in subplans (Tom Lane) If a CTE (WITH clause reference) is used in an InitPlan or SubPlan, and the query requires a recheck due to trying to update or lock a concurrently-updated row, incorrect results could be obtained.", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/003", "db_id": "9bf393cccf389e1408524d365c537615", "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb", "relations": [{"rule": 2, "type": "equivalent", "target": "4ac3c087eadec6a09af2ac698c7527e8", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}}, {"rule": 2, "type": "equivalent", "target": "557e981b12d86db91785cdce175221a5", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}}, {"rule": 2, "type": "equivalent", "target": "65c2b1f3aa8fcd6277735aeab8756942", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}}, {"rule": 2, "type": "equivalent", "target": "a8daaadc8ea647c9253fa0ea6edcdf0e", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}}], "version": "9.6.8", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": [{"db_id": "557e981b12d86db91785cdce175221a5", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "修复子计划中存在 CTE 引用时并发更新重新检查的错误行为", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}, "url": "/docs/compare/?release=10.3#10.3-a872d5a8564edde1", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "4ac3c087eadec6a09af2ac698c7527e8", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "修复子计划中出现 CTE 引用时并发更新重检查的错误行为", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}, "url": "/docs/compare/?release=9.5.12#9.5.12-a2a2d10a68caa3ed", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "65c2b1f3aa8fcd6277735aeab8756942", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "修复子计划中出现 CTE 引用时并发更新重检查的错误行为", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}, "url": "/docs/compare/?release=9.4.17#9.4.17-a2a2d10a68caa3ed", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "a8daaadc8ea647c9253fa0ea6edcdf0e", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "修复子计划中出现 CTE 引用时并发更新重检查的错误行为", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "5432474fe0549d18c17576b865b20cc16bfd43db793e3101d0b2a544761bbacb"}, "url": "/docs/compare/?release=9.3.22#9.3.22-a2a2d10a68caa3ed", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-179826c81b230b71", "cves": [], "html": "<p>修复外连接中重叠 mergejoin 子句导致的规划器失败（Tom Lane）</p>\n<p>这些错误在边界情况下导致 <span>“<span>left and right pathkeys do not match in mergejoin</span>”</span> 或 <span>“<span>outer pathkeys do not match mergeclauses</span>”</span> 规划器错误。</p>", "text": "修复外连接中重叠 mergejoin 子句导致的规划器失败（Tom Lane） 这些错误在边界情况下导致 “left and right pathkeys do not match in mergejoin” 或 “outer pathkeys do not match mergeclauses” 规划器错误。", "title": "修复外连接中重叠 mergejoin 子句导致的规划器失败", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "d576d7d55645300d80308749ec5b5297bab607c04d0a7531ea6e6004e9534122", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix planner failures with overlapping mergejoin clauses in an outer join (Tom Lane) These mistakes led to left and right pathkeys do not match in mergejoin or outer pathkeys do not match mergeclauses planner errors in corner cases.", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/004", "db_id": "9cc2fe244dd7f351eac0b31733b2d757", "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c", "relations": [{"rule": 2, "type": "equivalent", "target": "0246ca748e8808601f2952aaf477bc7d", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}}, {"rule": 2, "type": "equivalent", "target": "112e761317a2a41a3ad1e08f6759cb18", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}}, {"rule": 2, "type": "equivalent", "target": "56fa2fc847577a89467780f69c68e5f3", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}}, {"rule": 2, "type": "equivalent", "target": "9aada7ac4c7520858d32cdd00dd57e1f", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}}], "version": "9.6.8", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": [{"db_id": "0246ca748e8808601f2952aaf477bc7d", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "修复外连接中存在重叠归并连接子句时规划器失败的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}, "url": "/docs/compare/?release=10.3#10.3-839b6a412f88926e", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "112e761317a2a41a3ad1e08f6759cb18", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "修复外连接中重叠 mergejoin 子句导致的规划器失败", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}, "url": "/docs/compare/?release=9.5.12#9.5.12-179826c81b230b71", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "56fa2fc847577a89467780f69c68e5f3", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "修复外连接中重叠 mergejoin 子句导致的规划器失败", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}, "url": "/docs/compare/?release=9.4.17#9.4.17-179826c81b230b71", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "9aada7ac4c7520858d32cdd00dd57e1f", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "修复外连接中重叠 mergejoin 子句导致的规划器失败", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "d46b6a0d8a8b14ab6d44be2c4975c36de0dcd287333c7ce57b1d6285931eb26c"}, "url": "/docs/compare/?release=9.3.22#9.3.22-179826c81b230b71", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-2464e26a56508e56", "cves": [], "html": "<p>修复 <span>pg_upgrade</span> 未能为物化视图保留 <code>relfrozenxid</code> 的问题（Tom Lane、Andres Freund）</p>\n<p>这一疏漏可能导致升级后物化视图中的数据损坏，表现为 <span>“<span>could not access status of transaction</span>”</span> 或 <span>“<span>found xmin from before relfrozenxid</span>”</span> 错误。很少刷新的物化视图，或只用 <code>REFRESH MATERIALIZED VIEW CONCURRENTLY</code> 维护的物化视图更可能出现问题。</p>\n<p>如果观察到这种损坏，可以通过刷新物化视图（不带 <code>CONCURRENTLY</code>）来修复。</p>", "text": "修复 pg_upgrade 未能为物化视图保留 relfrozenxid 的问题（Tom Lane、Andres Freund） 这一疏漏可能导致升级后物化视图中的数据损坏，表现为 “could not access status of transaction” 或 “found xmin from before relfrozenxid” 错误。很少刷新的物化视图，或只用 REFRESH MATERIALIZED VIEW CONCURRENTLY 维护的物化视图更可能出现问题。 如果观察到这种损坏，可以通过刷新物化视图（不带 CONCURRENTLY）来修复。", "title": "修复 pg_upgrade 未能为物化视图保留 relfrozenxid 的问题", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "a5788db0efa33d3edaa7ec50ed7ae54c616e5e97b80ed7cc0b46aec3c6ac57ae", "section_path": ["变更"], "commit_groups": [], "identity_text": "Repair pg_upgrade's failure to preserve relfrozenxid for materialized views (Tom Lane, Andres Freund) This oversight could lead to data corruption in materialized views after an upgrade, manifesting as could not access status of transaction or found xmin from before relfrozenxid errors. The problem would be more likely to occur in seldom-refreshed materialized views, or ones that were maintained only with REFRESH MATERIALIZED VIEW CONCURRENTLY. If such corruption is observed, it can be repaired by refreshing the materialized view (without CONCURRENTLY).", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/005", "db_id": "e9404b51f387085a208937d5e6a9fffe", "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5", "relations": [{"rule": 2, "type": "equivalent", "target": "267341483bb67f18762263a23a116a9a", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}}, {"rule": 2, "type": "equivalent", "target": "6ec91031a9df77ef7dd3930d1b4037a6", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}}, {"rule": 2, "type": "equivalent", "target": "809e86a4b23d7d03113dae5ef73ab9fb", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}}, {"rule": 2, "type": "equivalent", "target": "8c7f0090d3efdd2cd57229f28fd5b068", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}}], "version": "9.6.8", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": [{"db_id": "809e86a4b23d7d03113dae5ef73ab9fb", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "修复 pg_upgrade 未保留物化视图的 relfrozenxid 的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}, "url": "/docs/compare/?release=10.3#10.3-40183e31fae9fef5", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "8c7f0090d3efdd2cd57229f28fd5b068", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "修复 pg_upgrade 未能为物化视图保留 relfrozenxid 的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}, "url": "/docs/compare/?release=9.5.12#9.5.12-2464e26a56508e56", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "6ec91031a9df77ef7dd3930d1b4037a6", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "修复 pg_upgrade 未能为物化视图保留 relfrozenxid 的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}, "url": "/docs/compare/?release=9.4.17#9.4.17-2464e26a56508e56", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "267341483bb67f18762263a23a116a9a", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "修复 pg_upgrade 未能为物化视图保留 relfrozenxid 的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "0f3fcc2128fc12d86be3cff82b0890b6675a4699af19d5ae2ade404e1e4da7c5"}, "url": "/docs/compare/?release=9.3.22#9.3.22-2464e26a56508e56", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-e08582093695d39b", "cves": [], "html": "<p>修复错误 <code>CONTEXT</code> 栈中 PL/Python 函数名的错误报告（Tom Lane）</p>\n<p>嵌套 PL/Python 函数调用（即通过 SPI 查询从另一个 PL/Python 函数到达的调用）中发生的错误会导致栈跟踪把内层函数名显示两次，而不是预期的结果。此外，嵌套 PL/Python <code>DO</code> 块中的错误在某些平台上可能导致空指针解引用崩溃。</p>", "text": "修复错误 CONTEXT 栈中 PL/Python 函数名的错误报告（Tom Lane） 嵌套 PL/Python 函数调用（即通过 SPI 查询从另一个 PL/Python 函数到达的调用）中发生的错误会导致栈跟踪把内层函数名显示两次，而不是预期的结果。此外，嵌套 PL/Python DO 块中的错误在某些平台上可能导致空指针解引用崩溃。", "title": "修复错误 CONTEXT 栈中 PL/Python 函数名的错误报告", "commits": [], "section": "变更", "category": "bugfix", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "b98fb22e5635ceae0cb72f14a42fe4bb86ab4cdf751364d3bec56d9ffd67ad1b", "section_path": ["变更"], "commit_groups": [], "identity_text": "Fix incorrect reporting of PL/Python function names in error CONTEXT stacks (Tom Lane) An error occurring within a nested PL/Python function call (that is, one reached via a SPI query from another PL/Python function) would result in a stack trace showing the inner function's name twice, rather than the expected results. Also, an error in a nested PL/Python DO block could result in a null pointer dereference crash on some platforms.", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/006", "db_id": "641a7d3d3a936660de7b1adcb973d842", "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400", "relations": [{"rule": 2, "type": "equivalent", "target": "8efb22bf1c2808bb7eb3dd918acf092e", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}}, {"rule": 2, "type": "equivalent", "target": "8f7222d3e858041c70d5edc267115e70", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}}, {"rule": 2, "type": "equivalent", "target": "e61fc28c486ea88b24d944ad276d95f3", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}}, {"rule": 2, "type": "equivalent", "target": "ff5ece554dad73d86b0508d20401b0c9", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}}], "version": "9.6.8", "category_label": "BUG 修复", "also_in": [], "variants": [], "related_changes": [{"db_id": "8efb22bf1c2808bb7eb3dd918acf092e", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "修复错误 CONTEXT 堆栈中 PL/Python 函数名报告不正确的问题", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}, "url": "/docs/compare/?release=10.3#10.3-08c915c97e67156b", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "ff5ece554dad73d86b0508d20401b0c9", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "修复错误 CONTEXT 栈中 PL/Python 函数名的错误报告", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}, "url": "/docs/compare/?release=9.5.12#9.5.12-e08582093695d39b", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "e61fc28c486ea88b24d944ad276d95f3", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "修复错误 CONTEXT 栈中 PL/Python 函数名的错误报告", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}, "url": "/docs/compare/?release=9.4.17#9.4.17-e08582093695d39b", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "8f7222d3e858041c70d5edc267115e70", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "修复错误 CONTEXT 栈中 PL/Python 函数名的错误报告", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "95ac95eba01e2ab653ffd472aa6f6ad7b8e9c97aa1910cffde48c739c7051400"}, "url": "/docs/compare/?release=9.3.22#9.3.22-e08582093695d39b", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-b77c944da95a643c", "cves": [], "html": "<p>允许 <code>contrib/auto_explain</code> 的 <code>log_min_duration</code> 设置范围达到 <code>INT_MAX</code>，即约 24 天而不是 35 分钟（Tom Lane）</p>", "text": "允许 contrib/auto_explain 的 log_min_duration 设置范围达到 INT_MAX，即约 24 天而不是 35 分钟（Tom Lane）", "title": "允许 contrib/auto_explain 的 log_min_duration 设置范围达到 INT_MAX，即约 24 天而不是 35 分钟", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "509b02f465b3d3ea9db4169a8b4dc37fda747e26b989d429a5a9eb2594487e34", "section_path": ["变更"], "commit_groups": [], "identity_text": "Allow contrib/auto_explain's log_min_duration setting to range up to INT_MAX, or about 24 days instead of 35 minutes (Tom Lane)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/007", "db_id": "3fbe1d14bce68f7ca59bc906345df355", "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4", "relations": [{"rule": 2, "type": "equivalent", "target": "2a43d364e24fe16f64e31371c27a75b4", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}}, {"rule": 2, "type": "equivalent", "target": "39f018451dfc209d196591c749df6ecf", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}}, {"rule": 2, "type": "equivalent", "target": "d8e8bedb3712958c3ebb83d9907fb10b", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}}, {"rule": 2, "type": "equivalent", "target": "e539fab6105b8e64c5a0cf584c2f64e5", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}}], "version": "9.6.8", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": [{"db_id": "39f018451dfc209d196591c749df6ecf", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "允许 contrib/auto_explain 的 log_min_duration 设置最大达到 INT_MAX，即约 24 天，而非 35 分钟", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}, "url": "/docs/compare/?release=10.3#10.3-a9f080e9c7d9f1d0", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}, {"db_id": "e539fab6105b8e64c5a0cf584c2f64e5", "kind": "equivalent", "version": "9.5.12", "label": "9.5.12", "title": "允许 contrib/auto_explain 的 log_min_duration 设置范围达到 INT_MAX，即约 24 天而不是 35 分钟", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}, "url": "/docs/compare/?release=9.5.12#9.5.12-b77c944da95a643c", "source_url": "/docs/release/9.5.12/#id-1.11.6.18.5"}, {"db_id": "d8e8bedb3712958c3ebb83d9907fb10b", "kind": "equivalent", "version": "9.4.17", "label": "9.4.17", "title": "允许 contrib/auto_explain 的 log_min_duration 设置范围达到 INT_MAX，即约 24 天而不是 35 分钟", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}, "url": "/docs/compare/?release=9.4.17#9.4.17-b77c944da95a643c", "source_url": "/docs/release/9.4.17/#id-1.11.6.14.5"}, {"db_id": "2a43d364e24fe16f64e31371c27a75b4", "kind": "equivalent", "version": "9.3.22", "label": "9.3.22", "title": "允许 contrib/auto_explain 的 log_min_duration 设置范围达到 INT_MAX，即约 24 天而不是 35 分钟", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "eaadbfc5806e32dadac7996d8d66d54eae17f09c30b79d8aa2ef206c3bc6cfc4"}, "url": "/docs/compare/?release=9.3.22#9.3.22-b77c944da95a643c", "source_url": "/docs/release/9.3.22/#id-1.11.6.8.5"}]}, {"id": "9.6.8-8b5ce35665dd0bda", "cves": [], "html": "<p>把若干 GUC 变量标记为 <code>PGDLLIMPORT</code>，以便于把扩展模块移植到 Windows（Metin Doslu）</p>", "text": "把若干 GUC 变量标记为 PGDLLIMPORT，以便于把扩展模块移植到 Windows（Metin Doslu）", "title": "把若干 GUC 变量标记为 PGDLLIMPORT，以便于把扩展模块移植到 Windows", "commits": [], "section": "变更", "category": "improvement", "source_url": "/docs/release/9.6.8/#id-1.11.6.21.5", "source_hash": "4b99625145b923339461f2e24b6da63efcd517a1b07b1bc72486e2c8c8fc8db1", "section_path": ["变更"], "commit_groups": [], "identity_text": "Mark assorted GUC variables as PGDLLIMPORT, to ease porting extension modules to Windows (Metin Doslu)", "commit_aliases": [], "source_commits": [], "source_entry_id": "9.6.8/changes/008", "db_id": "c0571cdf8adad607d1dc42bf43979318", "patch_ids": [], "statement_hash": "fbfd62b69c2a2f2c68aaf7ab8a4791729ed4d5433680a56bbc2482e797ea5b4a", "relations": [{"rule": 2, "type": "equivalent", "target": "7c95bb8479877165a6b12af8a0330d6c", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "fbfd62b69c2a2f2c68aaf7ab8a4791729ed4d5433680a56bbc2482e797ea5b4a"}}], "version": "9.6.8", "category_label": "其他改进", "also_in": [], "variants": [], "related_changes": [{"db_id": "7c95bb8479877165a6b12af8a0330d6c", "kind": "equivalent", "version": "10.3", "label": "10.3", "title": "将多个 GUC 变量标记为 PGDLLIMPORT，以便将扩展模块移植到 Windows", "evidence": {"same_day": true, "patch_ids": [], "statement_hash": "fbfd62b69c2a2f2c68aaf7ab8a4791729ed4d5433680a56bbc2482e797ea5b4a"}, "url": "/docs/compare/?release=10.3#10.3-a69652ba806045b1", "source_url": "/docs/release/10.3/#id-1.11.6.25.5"}]}]}], "stats": [{"key": "all", "label": "全部变更", "count": 8}, {"key": "feature", "label": "新功能", "count": 0}, {"key": "bugfix", "label": "BUG 修复", "count": 4}, {"key": "security", "label": "安全相关", "count": 2}, {"key": "performance", "label": "性能改进", "count": 0}, {"key": "compatibility", "label": "兼容性变化", "count": 0}, {"key": "improvement", "label": "其他改进", "count": 2}], "total": 8, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2018-1058", "url": "https://www.postgresql.org/support/security/CVE-2018-1058/", "fixed": {"10": "10.3", "9.3": "9.3.22", "9.4": "9.4.17", "9.5": "9.5.12", "9.6": "9.6.8"}, "score": 8.8, "title": "记录如何配置安装和应用以防受其他用户依赖 search_path 的特洛伊木马攻击", "vector": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "affected": {"10": "10", "9.3": "9.3", "9.4": "9.4", "9.5": "9.5", "9.6": "9.6"}, "component": "client", "published": {"10": "2018-03-01", "9.3": "2018-03-01", "9.4": "2018-03-01", "9.5": "2018-03-01", "9.6": "2018-03-01"}, "introduced": {}, "cvss_version": "3.0", "description_en": "", "first_published": "2018-03-01", "fixed_version": "9.6.8"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 8, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}