summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2010-10-02Behave correctly if INSERT ... VALUES is decorated with additional clauses.Tom Lane
In versions 8.2 and up, the grammar allows attaching ORDER BY, LIMIT, FOR UPDATE, or WITH to VALUES, and hence to INSERT ... VALUES. But the special-case code for VALUES in transformInsertStmt() wasn't expecting any of those, and just ignored them, leading to unexpected results. Rather than complicate the special-case path, just ensure that the presence of any of those clauses makes us treat the query as if it had a general SELECT. Per report from Hitoshi Harada.
2010-10-02Remove excess argument to open(2).Tom Lane
Many compilers don't complain about this, but some do, and it's certainly wrong. Back-patch to 8.4 where the error was introduced. Mark Kirkwood
2010-10-02Throw an appropriate error if ALTER COLUMN TYPE finds a dependent trigger.Tom Lane
Actually making this case work, if the column is used in the trigger's WHEN condition, will take some new code that probably isn't appropriate to back-patch. For now, just throw a FEATURE_NOT_SUPPORTED error rather than allowing control to reach the "unexpected object" case. Per bug #5688 from Daniel Grace. Back-patch to 9.0 where the possibility of such a dependency was introduced.
2010-10-01Fix back-branch breakage from ill-advised last-minute commit.REL9_0_1Tom Lane
2010-10-01Tag 9.0.1Marc G. Fournier
2010-09-30Use a separate interpreter for each calling SQL userid in plperl and pltcl.Tom Lane
There are numerous methods by which a Perl or Tcl function can subvert the behavior of another such function executed later; for example, by redefining standard functions or operators called by the target function. If the target function is SECURITY DEFINER, or is called by such a function, this means that any ordinary SQL user with Perl or Tcl language usage rights can do essentially anything with the privileges of the target function's owner. To close this security hole, create a separate Perl or Tcl interpreter for each SQL userid under which plperl or pltcl functions are executed within a session. However, all plperlu or pltclu functions run within a session still share a single interpreter, since they all execute at the trust level of a database superuser anyway. Note: this change results in a functionality loss when libperl has been built without the "multiplicity" option: it's no longer possible to call plperl functions under different userids in one session, since such a libperl can't support multiple interpreters in one process. However, such a libperl already failed to support concurrent use of plperl and plperlu, so it's likely that few people use such versions with Postgres. Security: CVE-2010-3433
2010-09-30Adjust pg_archivecleanup docs to match message changes made 2010-06-17.Robert Haas
Erik Rijkers
2010-09-30Translation updates for 9.0.1Peter Eisentraut
2010-09-30Update release notes for releases 9.0.1, 8.4.5, 8.3.12, 8.2.18, 8.1.22,Tom Lane
8.0.26, and 7.4.30.
2010-09-29Have pg_upgrade use strtoul(), not strtol().Bruce Momjian
2010-09-28Use macro atooid() for conversion of strings to oids, per suggestionBruce Momjian
from Tom.
2010-09-28In pg_upgrade, properly handle oids > 2^31 by using strtoul() internallyBruce Momjian
rather than atol(). Per report from Brian Hirt
2010-09-28Fix leak patch that was using fclose() instead of close().Bruce Momjian
2010-09-28Properly close files after read file failure to prevent potentialBruce Momjian
resource leak. Of course, any such failure aborts pg_upgrade, but might as well be clean about it. Per patch from Grzegorz Ja?kiewicz.
2010-09-28Fix another small oversight in command_no_begin patch.Tom Lane
Need a "return false" to prevent tests from continuing after we've moved the "query" pointer. As it stood, it'd accept "DROP DISCARD ALL" as a match.
2010-09-28Mention that pg_upgrade requires write permission in the currentBruce Momjian
directory. Per report from Harald Armin Massa.
2010-09-28Mention in pg_upgrade docs that the proper Win32 service name should be used.Bruce Momjian
Per report from Harald Armin Massa
2010-09-28Fix PlaceHolderVar mechanism's interaction with outer joins.Tom Lane
The point of a PlaceHolderVar is to allow a non-strict expression to be evaluated below an outer join, after which its value bubbles up like a Var and can be forced to NULL when the outer join's semantics require that. However, there was a serious design oversight in that, namely that we didn't ensure that there was actually a correct place in the plan tree to evaluate the placeholder :-(. It may be necessary to delay evaluation of an outer join to ensure that a placeholder that should be evaluated below the join can be evaluated there. Per recent bug report from Kirill Simonov. Back-patch to 8.4 where the PlaceHolderVar mechanism was introduced.
2010-09-28Add mention of installing pg_upgrade_support in pg_upgrade doc sectionBruce Momjian
title, per suggestion from Ian Barwick.
2010-09-28Only DISCARD ALL should be in the command_no_begin list.Itagaki Takahiro
We allowes DISCARD PLANS and TEMP in a transaction.
2010-09-28Add DISCARD to the command_no_begin list for AUTOCOMMIT=off.Itagaki Takahiro
Backpatch to 8.3. Reported by Sergey Burladyan.
2010-09-27Add "(change requires restart)" note to some postgresql.conf parameters.Robert Haas
Devrim GÜNDÜZ
2010-09-25Fix another join removal bug: the check on PlaceHolderVars was wrong.Tom Lane
The previous coding would decide that join removal was unsafe upon finding a PlaceHolderVar that needed to be evaluated at the inner rel and then used above the join. However, this fails to cover the case of PlaceHolderVars that refer to both the inner rel and some other rels. Per bug report from Andrus.
2010-09-25Further fixes to the pg_get_expr() security fix in back branches.Tom Lane
It now emerges that the JDBC driver expects to be able to use pg_get_expr() on an output of a sub-SELECT. So extend the check logic to be able to recurse into a sub-SELECT to see if the argument is ultimately coming from an appropriate column. Per report from Thomas Kellerer.
2010-09-25Fix man page markup for <cmdsynopsis> with multiple variantsPeter Eisentraut
Command synopses using <cmdsynopsis> with multiple variants previously used <sbr> to break lines between variants. The new man page toolchain introduced in 9.0 makes a mess out of that, and that markup was probably wrong all along, because <sbr> is supposed to break lines within a synopsis, not between them. So fix that by using multiple <cmdsynopsis> elements inside <refsynopsisdiv>. backpatched to 9.0
2010-09-24Still more .gitignore cleanup.Tom Lane
Fix overly-enthusiastic ignores, as identified by git ls-files -i --exclude-standard
2010-09-23Add contrib/xml2/pgxml.sql to .gitignoreRobert Haas
Kevin Grittner
2010-09-23ProcessIncomingNotify *must* reset notifyInterruptOccurred when called.Tom Lane
This was broken in 9.0 by careless addition of an early-exit path. Bug report and diagnosis by Jeff Davis.
2010-09-23Prevent show_session_authorization from crashing when session_authorizationTom Lane
hasn't been set. The only known case where this can happen is when show_session_authorization is invoked in an autovacuum process, which is possible if an index function calls it, as for example in bug #5669 from Andrew Geery. We could perhaps try to return a sensible value, such as the name of the cluster-owning superuser; but that seems like much more trouble than the case is worth, and in any case it could create new possible failure modes. Simply returning an empty string seems like the most appropriate fix. Back-patch to all supported versions, even those before autovacuum, just in case there's another way to provoke this crash.
2010-09-23Avoid sharing subpath list structure when flattening nested AppendRels.Tom Lane
In some situations the original coding led to corrupting the child AppendRel's subpaths list, effectively adding other members of the parent's list to it. This was usually masked because we never made any further use of the child's list, but given the right combination of circumstances, we could do so. The visible symptom would be a relation getting scanned twice, as in bug #5673 from David Schmitt. Backpatch to 8.2, which is as far back as the risky coding appears. The example submitted by David only fails in 8.4 and later, but I'm not convinced that there aren't any even-more-obscure cases where 8.2 and 8.3 would fail.
2010-09-23Initialize tableoid field correctly when dumping foreign data wrappers andHeikki Linnakangas
servers. AFAICT it's harmless at the moment because nothing can depend on either, but as soon as we introduce an object type with such dependencies, tableoid needs to be set or pg_dump will fail to interpret the dependencies correctly. In theory, I guess the uninitialized garbage in tableoid could cause the object to be mistaken for some other object with same OID as well.
2010-09-22Re-allow input of Julian dates prior to 0001-01-01 AD.Tom Lane
This was unintentionally broken in 8.4 while tightening up checking of ordinary non-Julian date inputs to forbid references to "year zero". Per bug #5672 from Benjamin Gigot.
2010-09-22More fixes for libpq's .gitignore file.Tom Lane
The previous patches failed to cover a lot of symlinks that are only added in platform-specific cases. Make the lists match what's in the Makefile for each branch.
2010-09-22Do some copy-editing on the Git usage docs.Tom Lane
2010-09-22Fix remaining stray references to CVS.Tom Lane
These are just cosmetic and don't seem worth back-patching far. I put them into 9.0 just because it was trivial to do so.
2010-09-22Add assorted other documentation build targets to documentation gitignore.Tom Lane
2010-09-22Some more gitignore cleanups: cover contrib and PL regression test outputs.Tom Lane
Also do some further work in the back branches, where quite a bit wasn't covered by Magnus' original back-patch.
2010-09-22Add gitignore files for ecpg regression tests.Magnus Hagander
Backpatch to 8.2 as that's how far the structure looks the same.
2010-09-22Remove anonymous cvs instructions, and replace them with instructionsMagnus Hagander
for git. Change other references from cvs to git as well.
2010-09-22Convert cvsignore to gitignore, and add .gitignore for build targets.Magnus Hagander
2010-09-21Fix a missed explanation of auto-analyze threshold, per Joe Miller.Tom Lane
2010-09-21Back-patch replacement of README.CVS with README.git.Tom Lane
In older branches, also git-ify the "make distdir" rule.
2010-09-17Move pg_db_role_setting docs to correct place in alphabetical order.Robert Haas
2010-09-17tag v9.0.0 ... the big day approachesREL9_0_0Marc G. Fournier
2010-09-16Treat exit code 128 (ERROR_WAIT_NO_CHILDREN) as non-fatal on Win32,Magnus Hagander
since it can happen when a process fails to start when the system is under high load. Per several bug reports and many peoples investigation. Back-patch to 8.4, which is as far back as the "deadman-switch" for shared memory access exists.
2010-09-16Translation updates for 9.0.0Peter Eisentraut
2010-09-16Stamp 9.0 release notes with expected release date; also some last-minuteTom Lane
copy-editing.
2010-09-16Fix bad grammar.Tom Lane
2010-09-16Fix two new-in-9.0 bugs in hstore.Tom Lane
There was an incorrect Assert in hstoreValidOldFormat(), which would cause immediate core dumps when attempting to work with pre-9.0 hstore data, but of course only in an assert-enabled build. Also, ghstore_decompress() incorrectly applied DatumGetHStoreP() to a datum that wasn't actually an hstore, but rather a ghstore (ie, a gist signature bitstring). That used to be harmless, but could now result in misbehavior if the hstore format conversion code happened to trigger. In reality, since ghstore is not marked toastable (and doesn't need to be), this function is useless anyway; we can lobotomize it down to returning the passed-in pointer. Both bugs found by Andrew Gierth, though this isn't exactly his proposed patch.
2010-09-15Add a compatibility note about plpgsql's treatment of SELECT INTO rec.fldTom Lane
when fld is of composite type. Per discussion of bug #5644 from Valentine Gogichashvili.