Path to this page:
Subject: CVS commit: pkgsrc
From: Adam Ciarcinski
Date: 2024-11-16 11:13:53
Message id: 20241116101353.C1084FC7D@cvs.NetBSD.org
Log Message:
postgresql: updated to 17.1, 16.5, 15.9, 14.14, 13.17
PostgreSQL 12 is now end-of-life.
Security Issues
* CVE-2024-10976: PostgreSQL row security below e.g. subqueries disregards user \
ID changes
* CVE-2024-10977: PostgreSQL libpq retains an error message from man-in-the-middle
* CVE-2024-10978: PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong \
user ID
* CVE-2024-10979: PostgreSQL PL/Perl environment variable changes execute \
arbitrary code
Bug Fixes and Improvements
This update fixes over 35 bugs that were reported in the last several months. \
The issues listed below affect PostgreSQL 17. Some of these issues may also \
affect other supported versions of PostgreSQL.
Fix when attaching or detaching table partitions with foreign key constraints. \
After upgrade, users impacted by this issue will need to perform manual steps to \
finish fixing it. Please see the "Upgrading" section and the release \
notes for more information.
Fix when using libc as the default collation provider when LC_CTYPE is C while \
LC_COLLATE is a different locale. This could lead to incorrect query results. If \
you have these settings in your database, please reindex any affected indexes \
after updating to this release. This issue impacted 17.0 only.
Several query planner fixes, including disallowing joining partitions \
(partitionwise join) if the collations of the partitions don't match.
Fix possible wrong answers or wrong varnullingrels planner errors for MERGE ... \
WHEN NOT MATCHED BY SOURCE actions.
Fix validation of the COPY FORCE_NOT_NULL and FORCE_NULL.
Fix server crash when a json_objectagg() call contains a volatile function.
Ensure there's a registered dependency between a partitioned table and a \
non-built-in access method specified in CREATE TABLE ... USING. This fix only \
prevents problems for partitioned tables created after this update.
Fix race condition in committing a serializable transaction.
Fix race condition in COMMIT PREPARED that could require manual file removal \
after a crash-and-recovery.
Fix for pg_cursors view to prevent errors by excluding cursors that aren't \
completely set up.
Reduce logical decoding memory consumption.
Fix to prevent stable functions from receiving stale row values when they're \
called from a CALL statement's argument list and the CALL is within a PL/pgSQL \
EXCEPTION block.
Fix for JIT crashes on ARM (aarch64) systems.
The psql \watch now treats values that are less than 1ms to be 0 (no wait \
between executions).
Fix failure to use credentials for a replication user in the password file (pgpass)
pg_combinebackup now throws an error if an incremental backup file is present in \
a directory that should contain a full backup.
Fix to avoid reindexing temporary tables and indexes in vacuumdb and parallel \
reindexdb
Files: