September 24, 2026: PostgreSQL 19 Beta 4 Released!

pg_vault_tde v1.7.2 : Critical crash fixes, new on-disk format, and stability improvements

Posted on 2026-10-05 by Miriade Srl
Related Open Source

Version 1.7.2 of pg_vault_tde is now available. This is a binary patch release where extension version stays at 1.7, but users can distinguish the build at runtime using pg_vault_tde_build_version().

This update focuses on critical stability, security, and correctness fixes:

  • New On-Disk Tuple Layout (v5): Introduces a walkable structure to fix a critical segmentation fault on UPDATE operations for tables with indexed variable-length columns (PSQLE-165).
  • TOAST Crash Resolved: Fixes a segfault triggered when values crossed the TOAST_TUPLE_THRESHOLD only after being encrypted. Furthermore, a bug where an all-NULL row made its table unreadable has been fixed.
  • tde_btree Hardening: The tde_btree index now strictly answers equality queries only, preventing incorrect row returns on range operators, ORDER BY, or merge joins (PSQLE-173).
  • Key Management & Reliability: Addresses data loss and corruption vulnerabilities in rotate_online() concurrent access (PSQLE-184), local wallet KEK rotation (PSQLE-185), and vault-to-wallet migrations (PSQLE-188).
  • WAL & Logical Decoding: Fixes memory accounting drift in logical decoding (PSQLE-186) and moves the Custom WAL resource manager ID from 128 to the registered ID 161 (PSQLE-172).
  • New script/checking improvement : The development process now includes ASan testing, Semgrep security checks, extended soak testing, and release signing with a generated SBOM (PSQLE-180, PSQLE-181, PSQLE-182).

Critical Upgrade Instructions:

  • Due to the WAL resource manager ID change, the upgrade requires a clean shutdown. If toast_custom_rmgr is turned on, the primary and standbys must be upgraded together, as a rolling upgrade is not possible.
  • Users must run VACUUM FULL on every encrypted table after the upgrade. Existing rows in the v4 format remain readable but will crash on UPDATE until they are rewritten to the v5 layout.

For a complete list of fixes and detailed upgrade procedures, please refer to the ROADMAP.md file.