Version 1.7.2 of pg_vault_tde is now available. This is a binary patch release where extension version stays at 1.7, but users can distinguish the build at runtime using pg_vault_tde_build_version().
This update focuses on critical stability, security, and correctness fixes:
UPDATE operations for tables with indexed variable-length columns (PSQLE-165).TOAST_TUPLE_THRESHOLD only after being encrypted. Furthermore, a bug where an all-NULL row made its table unreadable has been fixed.tde_btree index now strictly answers equality queries only, preventing incorrect row returns on range operators, ORDER BY, or merge joins (PSQLE-173).rotate_online() concurrent access (PSQLE-184), local wallet KEK rotation (PSQLE-185), and vault-to-wallet migrations (PSQLE-188).Critical Upgrade Instructions:
toast_custom_rmgr is turned on, the primary and standbys must be upgraded together, as a rolling upgrade is not possible.VACUUM FULL on every encrypted table after the upgrade. Existing rows in the v4 format remain readable but will crash on UPDATE until they are rewritten to the v5 layout.For a complete list of fixes and detailed upgrade procedures, please refer to the ROADMAP.md file.