WarehousePG 7.x release notes v7.6

The WarehousePG documentation describes the latest version of WarehousePG 7.

VersionRelease date
7.6.0-WHPG25 September 2026
7.5.0-WHPG8 June 2026
7.4.1-WHPG11 June 2026
7.4.0-WHPG7 April 2026
7.3.2-WHPG11 June 2026
7.3.1-WHPG30 January 2026
7.3.0-WHPG14 November 2025
7.2.2-WHPG17 November 2025
7.2.1-WHPG15 May 2025

WarehousePG 7.6.0-WHPG

Released: 25 September 2026

WarehousePG 7.6.0-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Critical security fix: server-side file functions were executable by any role

pg_file_write(), pg_file_rename(), pg_file_unlink(), and pg_logdir_ls() were executable by any database role, letting any authenticated user write, rename, or delete files in the coordinator's data and log directories, including postgresql.auto.conf and pg_hba.conf, and list server log file names. These functions now require superuser privileges or membership in pg_write_server_files (pg_read_server_files for pg_logdir_ls()).

This issue affects every WarehousePG 7 release before 7.6.0-WHPG. WarehousePG 6 isn't affected. Upgrade to 7.6.0-WHPG as soon as possible. See Applying the file function privilege fix for the required follow-up step and a mitigation script if you can't upgrade right away.

Note

WarehousePG 7.6.0 also changes some behaviors that need action when you upgrade, including dump output format, resource group CPUSET parsing, and pgcrypto and psql behavior. Review Replacing binaries and restarting WHPG before you upgrade.

New features

Enhancements

  • gpcheckperf now mirrors its output to ~/gpAdminLogs/gpcheckperf_<date>.log.
  • Lowered the dump syncmate snapshot log message from LOG to DEBUG5 to reduce log volume.

Bug fixes

  • Fixed a heap overrun in gp_get_endpoints() when parallel retrieve cursor endpoints exist in more than one database on the coordinator.
  • Fixed autovacuum's alive-session table and the resource group I/O-limit table to hash fixed-size keys as binary data, preventing out-of-bounds reads and key aliasing.
  • Fixed a SIGSEGV when rewriting multiple distinct-qualified aggregates (MDQA) over a partitioned table in the ORCA optimizer.
  • Fixed an ORCA crash on ordered-set aggregates without direct arguments, such as mode() WITHIN GROUP (...).
  • Fixed duplicated rows from percentile_cont() and percentile_disc() when they are the only aggregates over a grouped subquery.
  • Fixed a scalar-subquery count() result incorrectly folding to 0 when the aggregate row was eliminated by a filter or join, and fixed a use-after-free of a bare-variable HAVING qualifier during query normalization.
  • Fixed a coordinator SIGSEGV in extended-statistics estimation after incremental group statistics.
  • Fixed CTE consumer cardinality collapsing when join predicates are re-applied at every step of statistics calculation, which under-estimated rows and caused spilling to disk.
  • Fixed functional-dependency selectivity estimation, which the optimizer was dropping entirely, and fixed the estimate collapsing to one row when dependency statistics outlive a column's statistics.
  • Fixed ORCA planning wrong results for indexes whose key collation differs from the type default.
  • Fixed a backend crash on correlated subqueries that join a coordinator-only catalog table with a distributed table.
  • Fixed a planner crash on LEFT JOIN LATERAL over a UNION ALL that mixes a distributed-table arm with a VALUES arm and has an outer-query column in the target list. The query now fails with the ordinary could not devise a query plan error instead of crashing.
  • Fixed direct dispatch silently dropping rows for queries with a strewn-locus child, such as gp_dist_random() over a view with no FROM clause.
  • Fixed ERROR: ORDER/GROUP BY expression not found in targetlist for a correlated EXISTS sublink with both an aggregate and a GROUP BY clause.
  • Fixed append-optimized column-oriented (AOCO) unique indexes to catch conflicting keys consistently, preventing duplicate primary keys after gpfdist loads.
  • Fixed ERROR: ... is out of scanning scope for target relfilenode on append-optimized index fetches that run concurrently with VACUUM.
  • Fixed wrong results from the heap scan visibility cache for tuples carrying a combo command ID.
  • Fixed a PGresult leak on the query dispatcher for every distributed transaction protocol command.
  • Fixed execCurrentOf() to initialize the current table OID on the query dispatcher path for non-partitioned tables, and fixed version() to honor lightweight tags.
  • Fixed gp_dump_query_oids() to expand materialized views at any nesting depth, so minirepro collects the DDL of tables behind nested materialized views.
  • Fixed ALTER COLLATION ... REFRESH VERSION to dispatch to segments instead of updating only the coordinator's catalog.
  • Fixed ddl_command_end event triggers failing or silently skipping CREATE EXTERNAL TABLE.
  • Added CREATE PROTOCOL and ALTER TYPE ... SET DEFAULT ENCODING to the commands collected for ddl_command_end event triggers.
  • Fixed pg_event_trigger_ddl_commands() erroring with cache lookup failed for objects dropped by the same statement, which broke SPLIT PARTITION and SPLIT DEFAULT PARTITION when an event trigger is installed.
  • Fixed the reversed coordinator and segment split of the resource group CPUSET configuration parameter.
  • Fixed gp_toolkit.gp_workfile_entries inflating workfile metrics once per gang process.
  • Fixed gpload raising UnboundLocalError: has_seq_bool when the target table has a SERIAL column.
  • Fixed gpload to pass arguments through its shell wrapper without word splitting, so paths with spaces work, and to fall back to $HOME/gpAdminLogs when the configured log file is unusable.
  • Fixed analyzedb raising [Errno 9] Bad file descriptor when the coordinator data directory is on NFS or EFS.
  • Fixed gpMgmt remote execution to report SSH failures instead of returning success with empty output.
  • Fixed PL/Perl array and tied-container handling for non-rectangular arrays, forged ARRAY objects, tied SETOF array references, and NULL SV * values.
  • Fixed pgcrypto to reset the global debug handler after a PGP pipeline error, so later calls no longer emit stray dbg: notices.
  • Fixed the datalen calculation in tsvectorrecv(), which over-counted position data and could set a varlena size larger than the allocation.
  • Fixed append-optimized column-oriented (AOCO) table compression changes made with ALTER TABLE ... SET/RESET (compresstype, compresslevel, blocksize) to propagate to every column without its own explicit ENCODING, and to actually re-encode existing data. The rewrite previously ran and paid its full I/O cost, but every column kept its old codec.
  • Fixed hot-standby readers of append-optimized tables hitting truncated or refilled segment files after a VACUUM recycled segment files out from under an older snapshot.
  • Fixed a hot standby losing every query with could not access status of transaction N after the primary truncated pg_distributedlog.
  • Fixed a segfault on a hot-standby coordinator at connection time in multi-host deployments where a host carries only mirror rows.

Security

  • Fixed memory disclosure and a possible crash from casting oid[] or int2[] arrays to oidvector or int2vector without validating array dimensions and null entries, for CVE-2026-2003.
  • Required superuser to attach a non-built-in selectivity estimator in CREATE OPERATOR and ALTER OPERATOR, and hardened the built-in estimators and the intarray extension's _int_matchsel() function against incorrect operand types, for CVE-2026-2004.
  • Fixed a buffer overflow in pgcrypto's pgp_pub_decrypt_bytea() function by bounding the session key length, for CVE-2026-2005.
  • Fixed a one-byte overread in GB18030 multibyte character handling and replaced pg_mblen() with length-checked variants across the server, for CVE-2025-4207 and CVE-2026-2006.
  • Fixed out-of-bound reads in ascii() on invalid multibyte input, along with related fixes to EUC_CN length handling, mb2wchar() on short input, PGP-decrypted text encoding validation, and SUBSTRING() on toasted multibyte values, for CVE-2026-18024.
  • Fixed selectivity estimation performing its permission checks against inheritance children instead of the parent table, which let row-level security policies and security-barrier views be bypassed, for CVE-2025-8713.
  • Wrapped plain-text output from pg_dump, pg_dumpall, and pg_restore in psql \restrict and \unrestrict markers, so a malicious server can't inject meta-commands executed at restore time, for CVE-2025-8714.
  • Stopped psql from performing backquote expansion on the \unrestrict argument, for CVE-2026-18408.
  • Stopped psql from executing in-line COPY ... FROM STDIN data as SQL after the COPY command fails, for CVE-2026-6464.
  • Added a USAGE privilege check on types used by stored expressions, ALTER TABLE ... OF, and CREATE TYPE ... AS RANGE, for CVE-2026-6470.
  • Hardened tsvector and tsquery construction against integer overflows in array_to_tsvector(), tsvectorrecv(), tsvectorout(), and QTN2QT(), for CVE-2026-14662.
  • Fixed pgcrypto to fail cipher initialization errors during PGP encryption instead of emitting unencrypted data, and added the ignore-cipher-failure=1 decryption option, passed in the options argument of pgp_sym_decrypt() and pgp_pub_decrypt(), to read back affected data, for CVE-2026-14663.
  • Fixed a buffer overrun in regular expression match and split functions on invalidly encoded input, for CVE-2026-14664.
  • Fixed scalarineqsel() to verify a constant's data type before treating it as a tid, for CVE-2026-14668.
  • Bounded the copy of overlength time zone abbreviations in to_char(), and hardened PL/Perl against tied Perl arrays and hashes, for CVE-2026-14669 and CVE-2026-14670.
  • Removed a stale per-backend plan cache in contrib/spi/refint's check_foreign_key() function that caused type confusion, and fixed a NULL-key segfault, for CVE-2026-14671.
  • Used overflow-safe allocation in pltcl and plperl, for CVE-2026-14677.
  • Fixed pg_trgm's gtrgm_picksplit() function reading past the end of the signature buffer for all-true datums, for CVE-2026-14678.
  • Guarded fixed-size argument arrays in the parser, executor, fmgr, PL/pgSQL, and pltcl against extreme argument counts, for CVE-2026-14679.
  • Rejected SQL-level calls to functions that take or return the internal type, and made aggregate combine functions return NULL honestly, for CVE-2026-14680.
  • Fixed integer overflow and out-of-bounds writes in fuzzystrmatch's Levenshtein distance functions by computing distances in 64-bit arithmetic, for CVE-2026-15742.
  • Fixed a memory disclosure and possible remote code execution vulnerability from a mismatch between a portal's tuple descriptor and the query's actual output during EXECUTE or FETCH, for CVE-2026-16239.
  • Fixed pg_dump assuming a fixed bound on the length of pg_proc.protrftypes, for CVE-2026-19385.

WarehousePG 7.5.0-WHPG

Released: 8 June 2026

WarehousePG 7.5.0-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Upgrade considerations

Python 3.11 requirement for PL/Python

WarehousePG 7.5.0 upgrades PL/Python from Python 3.9 to Python 3.11. The PL/Python interpreter now links against /usr/bin/python3.11 and requires the following packages on every node in the cluster:

  • python3.11
  • python3.11-psycopg2
  • python3.11-pyyaml

On internet-connected clusters, the package manager installs these dependencies automatically when upgrading. On air-gapped clusters, install them manually on all nodes before upgrading. See Performing a minor upgrade for details.

New features

Enhancements

  • Bundled the LLVM 21 library (libLLVM.so) with the WarehousePG package. LLVM and Clang no longer need to be installed separately on cluster nodes for JIT compilation.
  • Improved performance of AO/AOCS table sampling by using an adaptive tuples-per-block estimation algorithm.
  • Optimized the gp_toolkit.gp_resgroup_config view for improved query performance.

Bug fixes

  • Fixed gpconfig to correctly respect the gp_resource_group_cgroup_parent configuration parameter when verifying the cgroup root.
  • Fixed a buffer over-read in TranslateDXLDatumGenericToScalar() that could cause instability in the ORCA optimizer.
  • Fixed incorrect distinct qualified aggregate (DQA) type classification under HAVING clauses that could produce incorrect query results.
  • Fixed an issue where RelabelType was not stripped when pulling up distribution keys through binary-compatible casts in partitioned table scans, which could produce incorrect query plans.

Security

  • Hardened multiple modules against integer overflow vulnerabilities for CVE-2026-6473, including ltree, ts_headline, intarray, the regex engine, unicode_normalize, formatting.c, array_agg, and the hstore PL/Perl and PL/Python extensions.
  • Fixed a format-string vulnerability in timeofday() for CVE-2026-6474 where a crafted time zone setting could abuse the pg_strftime() %Z format specifier to cause crashes or corrupt server memory.
  • Fixed a path traversal vulnerability in pg_rewind for CVE-2026-6475 where paths received from a rogue endpoint could overwrite files outside the target directory.
  • Fixed a buffer overrun in the frontend large object interface (libpq) for CVE-2026-6477 where PQfn() could write beyond the end of the result buffer when the server returned more data than requested.
  • Added timing-safe comparisons for secret material in all authentication paths for CVE-2026-6478, covering SCRAM, MD5, RADIUS, and plain authentication methods.
  • Fixed a stack overflow vulnerability in ProcessStartupPacket() for CVE-2026-6479 where a malicious client could alternate SSL and GSS negotiation requests indefinitely to exhaust server stack space.
  • Fixed an SQL injection and buffer overrun vulnerability in the refint contrib module for CVE-2026-6637.

WarehousePG 7.4.1-WHPG

Released: 11 June 2026

WarehousePG 7.4.1-WHPG includes the following bug fixes and other changes:

Bug fixes

  • Fixed a build failure with LLVM 21 in the JIT compilation subsystem.

Security

  • Hardened multiple modules against integer overflow vulnerabilities for CVE-2026-6473, including ltree, ts_headline, intarray, the regex engine, unicode_normalize, formatting.c, array_agg, and the hstore PL/Perl and PL/Python extensions.
  • Fixed a format-string vulnerability in timeofday() for CVE-2026-6474 where a crafted time zone setting could abuse the pg_strftime() %Z format specifier to cause crashes or corrupt server memory.
  • Fixed a path traversal vulnerability in pg_rewind for CVE-2026-6475 where paths received from a rogue endpoint could overwrite files outside the target directory.
  • Fixed a buffer overrun in the frontend large object interface (libpq) for CVE-2026-6477 where PQfn() could write beyond the end of the result buffer when the server returned more data than requested.
  • Added timing-safe comparisons for secret material in all authentication paths for CVE-2026-6478, covering SCRAM, MD5, RADIUS, and plain authentication methods.
  • Fixed a stack overflow vulnerability in ProcessStartupPacket() for CVE-2026-6479 where a malicious client could alternate SSL and GSS negotiation requests indefinitely to exhaust server stack space.
  • Fixed an SQL injection and buffer overrun vulnerability in the refint contrib module for CVE-2026-6637.

WarehousePG 7.4.0-WHPG

Released: 7 April 2026

WarehousePG 7.4.0-WHPG includes the following new features, enhancements, bug fixes, and other changes:

New features

  • Introduced pg_stat_statements for WarehousePG, extending standard PostgreSQL statistics collection to include all segment nodes.
  • Implemented DISTRIBUTED COORDINATOR ONLY tables to allow metadata to reside exclusively on the coordinator node, supporting specialized use cases where extensions must access data during early-stage query processing before distributed execution begins.

Enhancements

  • Added automatic fallback to the Postgres planner when vchord indexes are present.
  • Simplified the gp_stat_progress_copy_summary view and corrected issues where NULL values were improperly handled.
  • Enabled the get_ao_compression_ratio() function to execute in query executors.
  • Optimized internal cluster communications by improving the performance of Interconnect (IC) UDP processes and eliminating stale file descriptor warnings, resulting in more stable and faster data exchange between nodes.

Bug fixes

  • Improved query planner accuracy for anti-joins and left anti-semi joins by resolving a double-calculation error in join selectivity. This fix resolves issues where underestimated join costs led to inefficient query plans, resulting in significantly faster performance for complex analytical workloads.
  • Resolved critical stability issues in the ORCA optimizer, including fixes for segmentation faults, infinite recursion, and improper motion creation on QE slices.
  • Fixed ORCA regr_count scalar subquery decorrelation to prevent planning errors during complex aggregations.
  • Resolved an issue where ORCA failed to handle views with unused CTEs after changes were made to underlying table structures.
  • Improved DXL translation by fixing the handling of required but unused columns.
  • Fixed gpcheckcat inconsistencies encountered when using the SCRAM-SHA-256 authentication algorithm.
  • Ensured initdb only evaluates errno when a system call explicitly fails, preventing successful directory operations from being incorrectly reported as errors due to residual error codes from previous tasks.
  • Ensured isolation2 test compatibility for Python 3.14 by explicitly setting the subprocess start method to fork, preventing cannot pickle TextIOWrapper errors caused by the change in Python's default process spawning behavior on Linux.

Security

  • Mitigated SQL injection risks in pg_dump and pg_dumpall for CVE-2025-8715 by ensuring object names containing newlines are properly sanitized before being written as comments in backup files, preventing a vulnerability where maliciously crafted names could execute arbitrary SQL during the restore process.
  • Fixed a heap buffer overflow vulnerability in libpq for CVE-2025-12818 by hardening memory allocation against integer overflows. This change implements stricter size_t calculations for large, untrusted inputs to ensure allocated buffers are sufficient for their contents.

WarehousePG 7.3.2-WHPG

Released: 11 June 2026

WarehousePG 7.3.2-WHPG includes the following bug fixes and other changes:

Bug fixes

  • Fixed a build failure with LLVM 21 in the JIT compilation subsystem.

Security

  • Hardened multiple modules against integer overflow vulnerabilities for CVE-2026-6473, including ltree, ts_headline, intarray, the regex engine, unicode_normalize, formatting.c, array_agg, and the hstore PL/Perl and PL/Python extensions.
  • Fixed a format-string vulnerability in timeofday() for CVE-2026-6474 where a crafted time zone setting could abuse the pg_strftime() %Z format specifier to cause crashes or corrupt server memory.
  • Fixed a path traversal vulnerability in pg_rewind for CVE-2026-6475 where paths received from a rogue endpoint could overwrite files outside the target directory.
  • Fixed a buffer overrun in the frontend large object interface (libpq) for CVE-2026-6477 where PQfn() could write beyond the end of the result buffer when the server returned more data than requested.
  • Added timing-safe comparisons for secret material in all authentication paths for CVE-2026-6478, covering SCRAM, MD5, RADIUS, and plain authentication methods.
  • Fixed a stack overflow vulnerability in ProcessStartupPacket() for CVE-2026-6479 where a malicious client could alternate SSL and GSS negotiation requests indefinitely to exhaust server stack space.
  • Fixed an SQL injection and buffer overrun vulnerability in the refint contrib module for CVE-2026-6637.

WarehousePG 7.3.1-WHPG

Released: 30 January 2026

WarehousePG 7.3.1-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Enhancements

  • Allowed parallel workers to retrieve combo command ids and distributed snapshots directly from Dynamic Shared Memory (DSM).
  • Implemented pipes instead of sockets to terminate poll() blocking immediately for faster process signaling.
  • Added native support for executing customscans within the engine.
  • Made the rescanforeignscan callback optional for foreign data wrappers to improve FDW compatibility.
  • Configured GDD to push transaction ids into waitgxids so the query dispatcher can wait on them effectively.
  • Appended the WarehousePG name to the end of the version string for better identification.
  • Replaced spinlocks with lwlocks at the instrumentation header to reduce CPU contention.
  • Implemented pipes instead of sockets to terminate poll() blocking immediately for faster process signaling.
  • Updated the build instructions for RHEL8 and RHEL9 systems.
  • Updated regression test outputs to reflect recent FDW rescan changes.

Bug fixes

  • Fixed a critical issue with shared snapshots in DSM to prevent potential data loss.
  • Resolved a crash in ORCA when processing percentile aggregates.
  • Fixed a crash and incorrect results when using distinct qualified aggregates (DQA) with a filter clause.
  • Initialized missing plannedstmt fields in ORCA to prevent execution errors.
  • Corrected the handling of required but unused columns during DXL translation.
  • Fixed an incorrect join type assignment when pulling up expression sub-links.
  • Adjusted the severity level to warning in ftsprobe.c under specific conditions to reduce log noise.
  • Removed the guc_no_show_all flag for the archive_timeout setting.
  • Fixed an invalid escape sequence in the recoveryinfo.py script.
  • Resolved an intermittent failure case in the pg_waldump tests.
  • Corrected the return type of gddctxgetmaxvid() to use DistributedTransactionId(uint64).
  • Removed the deprecated pkg_resources dependency from the Python environment.

WarehousePG 7.3.0-WHPG

Released: 14 November 2025

WarehousePG 7.3.0-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Enhancements

  • Enabled parallel workers context for index builds to improve creation speed.
  • Merged Postgres 12 llvm changes and implemented explicit llvmcontextref for JIT inlining.
  • Configured the system to insert WAL records uncompressed if compression fails, ensuring write continuity.
  • Updated the copy utility to print the specific errno for program pipes.
  • Prevented the sorting of in-memory tuples when a process has already been interrupted.
  • Enabled builds for the intarray and unaccent extensions.
  • Updated waitgxids to use int64 for better handling of transaction ids.
  • Added support for PL/Python2 testing.
  • Improved the reliability of error detection in status_check cases.
  • Updated the PR template and .editorconfig settings.

Bug fixes

  • High availability: Fixed mirror promotion failures related to WAL segment renaming.
  • Resolved a VACUUM issue on AOCS tables following an aborted ADD COLUMN transaction.
  • Corrected pg_exttable view outputs specifically for ARM systems.
  • Implemented recursive calls in the plan walker for MergeAppend to ensure plan integrity.
  • Fixed a logic error involving SubPlan PlaceHolderVar.
  • Removed extra blank lines in EXPLAIN output.
  • Silenced harmless fsync errors when parent directories are removed.
  • Fixed a NULL pointer error during COPY (SELECT) TO option validation.
  • Dispatched ICU collation comments correctly.
  • Stopped reporting compresstype, zlib, or zstd errors when not in the validation phase.
  • Fixed inconsistent test cases for REINDEX TABLE, REINDEX INDEX, and EXPLAIN FORMAT.
  • Fixed the gpcheckcat mix_distribution_policy test.
  • Replaced the deprecated Python pipes module.
  • Removed gsutil from developer requirements.

Security

WarehousePG 7.2.2-WHPG

Released: 17 November 2025

WarehousePG 7.2.2-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Enhancements

  • Enabled parallel workers context for index builds to reduce execution time.
  • Optimized resource usage by skipping the sorting of in-memory tuples when a process is interrupted.
  • Configured WAL records to be inserted uncompressed as a fallback if compression fails.
  • Enhanced diagnostic output by printing the specific errno for copy program pipes.
  • Improved concurrency handling by using int64 for waitgxids.
  • Enabled the unaccent extension by default.
  • Added PL/Python2 testing support for WarehousePG 7 environments.
  • Improved the reliability of error detection for status_check operations.

Bug fixes

  • Fixed a failure in mirror promotion caused by WAL segment renaming.
  • Resolved a vacuuming issue on AOCS tables that occurred after aborted add column transactions.
  • Corrected pg_exttable view data for ARM-based architectures.
  • Implemented recursive calls in the plan walker for mergeappend to ensure correct plan traversal.
  • Fixed a sub-plan bug related to placeholder variables.
  • Suppressed unnecessary blank lines in EXPLAIN output.
  • Prevented harmless fsync errors from being reported when parent directories are missing.
  • Ensured ICU collation comments are dispatched correctly to maintain metadata.
  • Stopped reporting compresstype errors during the non-validation phase.
  • Silenced zlib and zstd reloption errors during the non-validation phase.
  • Reverted the fault tolerance service (FTS) enablement for mirror-less clusters.
  • Resolved intermittent test failures in REINDEX TABLE and REINDEX INDEX cases.
  • Fixed an intermittent failure in the explain_format test case.
  • Fixed the gpcheckcat mix_distribution_policy test.
  • Removed the gsutil dependency from development requirements.

Security

WarehousePG 7.2.1-WHPG

Released: 15 May 2025 WarehousePG 7.2.1-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Enhancements

  • Fixed a work_mem reference in hash aggregates to ensure planned memory is fully utilized and reduce unnecessary disk spills.

Bug fixes

  • Resolved a gpstart failure caused by a double free or corruption error when using OpenSSL 3.2.2.
  • Fixed a bug in the Postgres planner where correlated subqueries returned incorrect results due to improper placeholdervar handling.
  • Resolved an unexpected gang size error occasionally encountered in the Postgres planner.
  • Initialized attnumswithentries to prevent failures during concurrent-only (CO) table rewrites.

Security