postgresql-8.4 (8.4.1-1) unstable; urgency=medium * Urgency medium due to security fix. * New upstream security/bug fix release: - Disallow "RESET ROLE" and "RESET SESSION AUTHORIZATION" inside security-definer functions. This covers a case that was missed in the previous patch that disallowed "SET ROLE" and "SET SESSION AUTHORIZATION" inside security-definer functions. [CVE-2007-6600] - Fix WAL page header initialization at the end of archive recovery. This could lead to failure to process the WAL in a subsequent archive recovery. - Fix "cannot make new WAL entries during recovery" error. - Fix problem that could make expired rows visible after a crash. This bug involved a page status bit potentially not being set correctly after a server crash. - Make "LOAD" of an already-loaded loadable module into a no-op. Formerly, "LOAD" would attempt to unload and re-load the module, but this is unsafe and not all that useful. - Make window function PARTITION BY and ORDER BY items always be interpreted as simple expressions. In 8.4.0 these lists were parsed following the rules used for top-level GROUP BY and ORDER BY lists. But this was not correct per the SQL standard, and it led to possible circularity. - Fix several errors in planning of semi-joins. These led to wrong query results in some cases where IN or EXISTS was used together with another join. - Fix handling of whole-row references to subqueries that are within an outer join. An example is SELECT COUNT(ss.-) FROM ... LEFT JOIN (SELECT ...) ss ON .... Here, ss.- would be treated as ROW(NULL,NULL,...) for null-extended join rows, which is not the same as a simple NULL. Now it is treated as a simple NULL. - Fix locale handling with plperl. This bug could cause the server's locale setting to change when a plperl function is called, leading to data corruption. - Fix handling of reloptions to ensure setting one option doesn't force default values for others. - Ensure that a "fast shutdown" request will forcibly terminate open sessions, even if a "smart shutdown" was already in progress. - Avoid memory leak for array_agg() in GROUP BY queries. - Treat to_char(..., 'TH') as an uppercase ordinal suffix with 'HH'/'HH12'. It was previously handled as 'th'. - Include the fractional part in the result of EXTRACT(second) and EXTRACT(milliseconds) for time and time with time zone inputs. This has always worked for floating-point datetime configurations, but was broken in the integer datetime code. - Fix overflow for INTERVAL 'x ms' when "x" is more than 2 million and integer datetimes are in use. - Improve performance when processing toasted values in index scans. This is particularly useful for PostGIS. - Fix a typo that disabled commit_delay. - Output early-startup messages to "postmaster.log" if the server is started in silent mode. Previously such error messages were discarded, leading to difficulty in debugging. - Remove translated FAQs. They are now on the wiki. The main FAQ was moved to the wiki some time ago. - Fix pg_ctl to not go into an infinite loop if "postgresql.conf" is empty. - Fix several errors in pg_dump's --binary-upgrade mode. pg_dump --binary-upgrade is used by pg_migrator. - Fix "contrib/xml2"'s xslt_process() to properly handle the maximum number of parameters (twenty). - Improve robustness of libpq's code to recover from errors during "COPY FROM STDIN". - Avoid including conflicting readline and editline header files when both libraries are installed. - Work around gcc bug that causes "floating-point exception" instead of "division by zero" on some platforms. * debian/control: Bump Standards-Version to 3.8.3 (no changes necessary). -- Martin Pitt Sun, 06 Sep 2009 14:11:13 +0200 postgresql-8.4 (8.4.0-2) unstable; urgency=low * debian/libpq-dev.install: Ship catalog/genbki.h. (Closes: #536139) * debian/rules: Drop --enable-cassert for final release. -- Martin Pitt Sat, 11 Jul 2009 16:59:35 +0200 postgresql-8.4 (8.4.0-1) unstable; urgency=low * Final 8.4.0 release. Major enhancements: - Windowing Functions - Common Table Expressions and Recursive Queries - Default and variadic parameters for functions - Parallel Restore - Column Permissions - Per-database locale settings - Improved hash indexes - Improved join performance for EXISTS and NOT EXISTS queries - Easier-to-use Warm Standby - Automatic sizing of the Free Space Map - Visibility Map (greatly reduces vacuum overhead for slowly-changing tables) - Version-aware psql (backslash commands work against older servers) - Support SSL certificates for user authentication - Per-function runtime statistics - Easy editing of functions in psql - New contrib modules: pg_stat_statements, auto_explain, citext, btree_gin Upload to unstable, 8.4 is the new default. * debian/control: Build the versionless metapackages and have them point to 8.4. -- Martin Pitt Wed, 01 Jul 2009 17:41:41 +0200 postgresql-8.4 (8.4~rc1-1) experimental; urgency=low * First release candidate of 8.4. -- Martin Pitt Mon, 22 Jun 2009 09:17:52 +0200 postgresql-8.4 (8.4~beta2-2) experimental; urgency=low * Second public beta of 8.4. * debian/control: Slightly lower the dependencies for postgresql-common to >= 98~, so that backports also match. -- Martin Pitt Tue, 19 May 2009 14:03:37 +0200 postgresql-8.4 (8.4~beta1+cvs20090503-1) experimental; urgency=low * New upstream snapshot. -- Martin Pitt Tue, 05 May 2009 00:58:06 +0200 postgresql-8.4 (8.4~beta1-1) experimental; urgency=low * First public beta of 8.4. * debian/*.install: Add new gettext translations. * debian/control: Bump p-common dependency to >= 98 to ensure support for 8.4. * debian/rules: Build with --enable-cassert while in beta. -- Martin Pitt Mon, 27 Apr 2009 08:35:30 +0200 postgresql-8.4 (8.4~0cvs20090328-1) experimental; urgency=low * Package current trunk, which will become 8.4 in time. Packaging branched from 8.3 packaging trunk. Move from cdbs' tarball.mk to bzr-builddeb. * Drop obsolete patches: - 03-gettext-domains.patch: Adopted upstream. - 04-psql-passwordprompt.patch: Obsoleted by new psql -w option. - 05-check-rlimits-nofile.patch: Adopted upstream. * Update remaining patches for new upstream version. * Add debian/docbook2man-sgmlspl/docbook2man-spec{.pl,_makelinks}: Current Debian version in docbook-utils is way too old and broken (see #275715, #271611), locally ship the current ones from upstream, in order to build manpages. * debian/rules: Build documentation and manpage tarballs if not present (as with building from CVS). Add necessary build dependencies docbook-utils, openjade, and docbook. -- Martin Pitt Fri, 20 Mar 2009 12:00:13 +0100