v4.7.0 Release Notes

Release date: August, 2026

Version: v4.7.0

SynxDB v4.7.0 improves data file lifecycle management and statistics collection for Apache Iceberg tables, unifies how lakehouse storage is configured and named, and adds tablespace-level transparent encryption backed by an external key management service.

  • Data federation and lakehouse integration: DROP TABLE, VACUUM, and the new TRUNCATE reclaim Iceberg data files from object storage; ANALYZE collects column statistics for Iceberg tables; site configuration file key names now match the SQL option names, and namespace resolution follows a fixed order; Azure Blob Storage and Google Cloud Storage join the supported object storage protocols.

  • Query processing and optimization: GPORCA plans and prunes hash-partitioned tables, and rewrites correlated scalar subqueries as window aggregates; a vectorized partition Top-K and per-worker execution statistics are also new.

  • Security: You can now encrypt selected tablespaces on a running cluster and let an external key management service (KMS) hold the key encryption key (KEK).

  • Storage: pg_dump now includes PAX tables in a plain-text dump.

  • Observability and reliability: DBCC adds PgBouncer connection pool monitoring and a resource group management page.

New features

Database

Category

Feature

User documents

Data federation and lakehouse integration

The key names in s3.conf, gphdfs.conf, and gphive.conf now match the SQL option names of the corresponding SERVER and USER MAPPING objects. The two sources merge per key, and an option written in SQL takes precedence.

Site configuration file key names

Data federation and lakehouse integration

The protocol option of a datalake_fdw foreign table accepts two new values, azure and gcs, so you can query data on Azure Blob Storage and Google Cloud Storage directly.

Load data from object storage

Data federation and lakehouse integration

An HDFS server accepts a new data_transfer_protection option, which lets you connect to a Kerberos HDFS cluster that enforces a specific protection level on data transfer.

Load data from HDFS

Data federation and lakehouse integration

CREATE FOREIGN CATALOG accepts a new polaris_server_realm option for a Polaris server that uses a custom realm.

Use a Polaris catalog

Data federation and lakehouse integration

The Hive Connector syncs EXTERNAL_TABLE, which matches the behavior of Hive 4.0 and later where CREATE TABLE creates an external table by default.

Load data from Hive data warehouse

Data federation and lakehouse integration

Catalog types that maintain a namespace directory resolve the namespace of each table in one fixed order: the table’s own namespace option first, then the default_namespace of the catalog.

How the namespace is resolved

Data federation and lakehouse integration

For an Iceberg table managed by a builtin catalog, DROP TABLE, VACUUM, and the new TRUNCATE reclaim its data files and metadata files from object storage.

Empty a table with TRUNCATE, What happens to the data files

Data federation and lakehouse integration

For a table managed by a builtin catalog, files now live directly under the base_path of the volume, which makes paths shorter and more predictable.

CREATE ICEBERG TABLE options

Data federation and lakehouse integration

CREATE ICEBERG TABLE accepts new compression and compression_level options that set the compression algorithm and level for the Parquet files it writes.

CREATE ICEBERG TABLE options

Data federation and lakehouse integration

Before it reads a data file, a scan on an Iceberg table prunes by the statistics of that file and skips a file whose value range does not overlap the predicate.

Column projection and filtering

Data federation and lakehouse integration

ANALYZE samples an Iceberg table and collects column statistics, including the number of distinct values, most common values, and histograms, the same way it does for other table types.

Collect statistics for Iceberg tables

Data federation and lakehouse integration

datalake.disable_cache_file applies to every lakehouse read path in the session, so one parameter controls the data file cache on the local disk of each segment.

Configuration parameters

Query processing and optimization

GPORCA plans hash-partitioned tables and prunes their partitions, so these tables no longer fall back to the Postgres optimizer for that reason.

Hash-partitioned tables

Query processing and optimization

GPORCA rewrites a correlated scalar subquery that aggregates on the join key into a window aggregate over the join result, removing one aggregation and one join from the plan.

Rewrite a correlated scalar subquery as a window aggregate

Query processing and optimization

A top-N-per-group query can use vectorized Top-K pushdown, where each segment prunes its own candidate rows before they cross the interconnect.

Run the optimization under the vectorized executor

Query processing and optimization

EXPLAIN ANALYZE reports row counts and timings per segment and per worker, which reveals data skew in a parallel plan.

Inspect per-worker statistics

Storage

pg_dump includes PAX tables in a plain-text dump and preserves the storage format, table-level options, per-column ENCODING attributes, and partition structure.

Back up and restore PAX tables, Choose a backup tool

Security

You can encrypt selected tablespaces on a running cluster, and a builtin, local_cmd, cosmian, or kmip external KMS can hold the key encryption key.

Encrypt a single tablespace

Interactive manager DBCC

Feature

User documents

Manages an existing PgBouncer deployment, collects throughput and connection statistics per pool, and restarts PgBouncer on a failed host automatically

Monitor PgBouncer connection pools

Creates, edits, and deletes resource groups, assigns database roles to them, and sets disk I/O limits per tablespace

Manage resource groups

Excludes selected mount points from the storage overview page, per host

Hide mount points from the view

New feature details

Data federation and lakehouse integration

  • Site configuration file key names match the SQL options: When you keep repeated storage settings in a site configuration file and reference them through server_name, the key names in s3.conf, gphdfs.conf, and gphive.conf now match the SQL option names of the corresponding SERVER and USER MAPPING objects exactly. The two sources merge per key. An option written in SQL takes precedence, and a key needed for metadata access falls back to the file when SQL leaves it out, so you no longer translate between two naming schemes. If you reuse a configuration file written for an earlier version, the old Hadoop-style key names are rejected, and the error lists every key in that section that needs a new name along with its replacement.

    See Site configuration file key names.

  • Azure Blob and GCS object storage: The protocol option of a datalake_fdw foreign table accepts two new values, azure and gcs, so you can create tables over data on Azure Blob Storage and Google Cloud Storage and query it directly, without exporting or staging it first. Both reuse the same option set as the other object storage protocols.

    See Load data from object storage.

  • HDFS data transfer protection level: An HDFS server accepts a new data_transfer_protection option, set to authentication, integrity, or privacy, which must match dfs.data.transfer.protection in the hdfs-site.xml of the cluster. On a Kerberos HDFS cluster that enforces a specific protection level on data transfer, the client and the DataNode cannot read the data through negotiation alone, and setting this option explicitly lets you connect. The option takes effect only when hdfs_auth_method is kerberos.

    See Load data from HDFS.

  • Configurable realm for a Polaris catalog: CREATE FOREIGN CATALOG accepts a new polaris_server_realm option for a Polaris server that uses a custom realm. Omitting the option uses POLARIS.

    See Use a Polaris catalog.

  • Sync Hive external tables: The Hive Connector now syncs EXTERNAL_TABLE, not only MANAGED_TABLE. This matters most for Hive 4.0 and later, where CREATE TABLE creates an EXTERNAL_TABLE by default, so syncing works without setting hive.create.as.external.legacy on the Hive side.

    See Load data from Hive data warehouse.

  • One rule for namespace resolution: The catalog types that maintain a namespace directory (hive, hadoop, and polaris) now resolve the namespace of each table in one order: the table’s own namespace option in CREATE ICEBERG TABLE first, then the default_namespace of the catalog. Multiple tables under the same catalog need the setting only once, and an individual table can still override it through the table-level option. When the resolved namespace has no matching database in the underlying catalog, the error states the resolution order and every way to correct it.

    See How the namespace is resolved.

  • Data file lifecycle for Iceberg tables: For an Iceberg table managed by a builtin catalog, the database now reclaims the data files and metadata files from object storage together with the table. DROP TABLE records the metadata tree of the table in a deletion queue, which an autovacuum-driven background consumer removes; VACUUM reclaims the rewritten old files once compaction finishes; and the new TRUNCATE empties the table and reclaims its original data files. All of these operations are transactional and delete no files when the statement rolls back, so lakehouse storage does not keep growing with the number of tables created and dropped.

    See Empty a table with TRUNCATE, Compact tables with VACUUM, and What happens to the data files.

  • Flat storage layout for builtin Iceberg tables: For a table managed by a builtin catalog, files now live directly under the base_path of the volume, which makes paths shorter and more predictable for external engines and for operators locating table data by path. All builtin tables on the same volume share one data directory and one metadata directory and the UUID in each file name keeps them apart, so avoid pointing maintenance tools that work on directory prefixes at this shared directory. Tables created earlier keep the path recorded at creation time and need no migration.

    See CREATE ICEBERG TABLE options.

  • Parquet write compression for Iceberg tables: CREATE ICEBERG TABLE accepts new compression and compression_level options that set the compression algorithm (zstd, snappy, gzip, lz4, or uncompress) and the compression level for the Parquet files it writes, so you can trade object storage footprint against write cost based on your data. The database validates both options on the first write to the table, and they cannot change afterward, so a different algorithm or level requires re-creating the table.

    See CREATE ICEBERG TABLE options.

  • File-level pruning for Iceberg table scans: Before it reads a data file, a scan on an Iceberg table now prunes by the statistics of that file and skips a file entirely when the value range of the predicate column does not overlap the predicate. On a table loaded in batches by time or by an increasing ID, the value ranges of the files do not overlap, so such queries do less scan I/O.

    See Column projection and filtering.

  • Collect statistics for Iceberg tables: ANALYZE now samples an Iceberg table and collects column statistics, including the number of distinct values, most common values, and histograms, the same way it does for other table types, so the optimizer plans lakehouse queries from the real data distribution. Without statistics, the optimizer estimates one row per Iceberg scan and produces plans that spill large amounts of data on a large table, so run ANALYZE once after loading an Iceberg table, and again after a write that changes the data distribution noticeably. ANALYZE also refreshes pg_class.reltuples to the effective row count of the table, which matches the result of SELECT count(*).

    See Collect statistics for Iceberg tables.

  • One switch for the lakehouse read cache: datalake.disable_cache_file now applies to every lakehouse read path in the session, including both datalake_fdw foreign tables and Iceberg tables, so one parameter controls the data file cache on the local disk of each segment. A datalake_fdw foreign table created with enablecache 'true' still uses the cache and overrides the session setting.

    See Configuration parameters.

Query processing and optimization

  • GPORCA support for hash-partitioned tables: GPORCA can now plan hash-partitioned tables and prune their partitions, so these tables no longer fall back to the Postgres optimizer for that reason. An equality predicate on the partition key prunes to the one partition that can hold the value, join-driven pruning works as well, and a range predicate does not narrow the set of partitions. The supported partition key is a single column on a single partitioning level; a composite hash key, an expression as the partition key, and hash subpartitions under range partitioning still fall back.

    See Hash-partitioned tables.

  • Rewrite a correlated scalar subquery as a window aggregate: When the aggregate in a correlated scalar subquery groups on the join key, and its correlation predicate and the outer join predicate fall on the same pair of keys, GPORCA can now compute that aggregate with a window function over the join result, which removes one aggregation, one join, and the second scan of the same table from the plan. optimizer_enable_scalar_subq_filter_pushdown controls the rewrite and defaults to off.

    See Rewrite a correlated scalar subquery as a window aggregate.

  • Vectorized partition Top-K: A top-N-per-group query of the form rank() OVER (PARTITION BY ... ORDER BY ...) <= K can use vectorized Top-K pushdown once both optimizer_force_partition_topk and vector.enable_vectorization are on, and the plan node is Vec Partition Top-K. When the partition column requires redistribution, one such node sits on each side of the Motion, and each segment prunes its candidate rows before they cross the interconnect, which reduces the data that takes part in sorting and network transfer.

    See Run the optimization under the vectorized executor.

  • Inspect per-worker statistics: With gp_enable_explain_allstat on, EXPLAIN ANALYZE prints a worker stats: block under each node, with one line of row count and timing per segment and per worker. The actual rows of a node reports a single number for the whole segment, whereas comparing the row counts of the workers within one segment reveals data skew in a parallel plan. This parameter is experimental and off by default. Use it in a test environment only.

    See Inspect per-worker statistics.

Storage

  • Back up and restore PAX tables: pg_dump now includes PAX tables in a plain-text dump, which it ignored before. The dump preserves the storage format, table-level options, the ENCODING attributes of each column, and the partition structure, and you restore it by running the SQL statements in the dump file. Use the plain-text format. Support for PAX tables in the -Fc, -Fd, and -Ft archive formats is incomplete, and such a run can report success while producing an unreliable backup.

    See Back up and restore PAX tables and Choose a backup tool.

Security

  • Tablespace-level transparent encryption with an external KMS: In addition to whole-cluster encryption, which you turn on when you initialize the cluster, you can now encrypt only selected tablespaces on a running cluster. Specify AES128, AES192, AES256, or SM4 through the encryption_method option of CREATE TABLESPACE, and every relation placed in that tablespace is encrypted. Each encrypted tablespace has its own data encryption key (DEK), and the key encryption key (KEK) that wraps it is held by an external key management service (KMS). tde_kms_provider supports four provider types, builtin, local_cmd, cosmian, and kmip, and the last two wrap and unwrap on the KMS server so that the KEK never leaves the KMS. The two mechanisms are independent, but tablespace-level encryption does not cover the WAL. Turn on cluster-level encryption as well when the WAL stream and its archive also need protection.

    See Encrypt a single tablespace.

Observability and reliability

  • Monitor PgBouncer connection pools: If clients reach the cluster through PgBouncer, DBCC can now manage an existing PgBouncer deployment and collect throughput and connection statistics per pool as time series. Together with the Pgbouncer Down alert template, the agent on a failed host restarts PgBouncer without manual work. Monitoring is off by default and an upgrade does not turn it on, so you enable both dbcc.pgbouncer.enabled on the server side and database.pgbouncer.enabled on each agent. PgBouncer itself is not part of the release package, and you deploy it yourself.

    See Monitor PgBouncer connection pools.

  • Manage resource groups: You can now create, edit, and delete resource groups in DBCC and assign database roles to them without writing SQL. The concurrency, CPU limit percentage, memory quota, and other fields come prefilled with usable defaults, and the page also sets disk I/O limits per tablespace. The page requires a cluster that uses resource groups rather than resource queues, and an I/O limit additionally requires gp_resource_manager set to group-v2.

    See Manage resource groups.

  • Hide mount points from the storage overview: The storage overview page can now exclude selected mount points. A mount point such as a large backup volume that every host mounts carries no useful information and takes an outsized share of the total. List the mount points to hide by host name under dbcc.storage.excludeMountPoints on the DBCC server, where the reserved key all applies to every host.

    See Hide mount points from the view.

Product change information

Upgrade notes

Note the following when you upgrade a cluster with gpupgrade. For details, see Upgrade using gpupgrade.

  • Before the upgrade, remove the source command for greenplum_path.sh and environment variable declarations such as COORDINATOR_DATA_DIRECTORY from ~/.bashrc and ~/.bash_profile on every cluster host, then run gpupgrade from a new shell. Otherwise, gpupgrade initialize fails at the environment check step.

  • gpinitsystem initializes the target cluster, so postgresql.conf and pg_hba.conf return to the defaults of the target version. Parameters set with gpconfig on the source cluster and timezone do not carry over, and the upgrade gives no warning about this. Back up both files before the upgrade, restore them afterward, and run gpstop -u to reload them.

  • The storage format of bitmap indexes and of BRIN indexes on AO and AOCO tables has changed, and both need a rebuild after the upgrade. A bitmap index still counts as valid, so the optimizer keeps using it and returns wrong results without an error. Rebuild these indexes before you restore application access.

  • The upgrade re-creates the public schema, and the PUBLIC role loses its USAGE and CREATE privileges on that schema.

  • Link mode reuses the data files of the source cluster through hard links, which requires the data directories of the source and target clusters to be on one file system. Use copy mode for a cluster whose data directories span multiple disk devices.

Behavior changes

  • Scans on Iceberg tables no longer use intra-segment parallelism until the related support is complete, which avoids wrong results and crashes on the parallel path. Scan task assignment across segments is unaffected.

  • The Hudi metadata table is now off by default, which avoids compatibility problems with that feature in the current integration.

GUC configuration parameters

Newly added GUCs

The following configuration parameters are added:

  • tde_kms_provider: default none. Selects the KMS provider that wraps the data encryption key of an encrypted tablespace. Valid values are none, builtin, cosmian, kmip, and local_cmd. See Choose a KMS provider.

  • tde_kms_host: default empty. Sets the host name or IP address of the KMS server. See Configure the KMS provider.

  • tde_kms_port: default 5696. Sets the port of the KMS server. See Configure the KMS provider.

  • tde_kms_username: default empty. Sets the user name used to connect to the KMS. See Configure the KMS provider.

  • tde_kms_ca_cert: default empty. Sets the path to the CA certificate that verifies the KMS server certificate. See Configure the KMS provider.

  • tde_kms_client_cert: default empty. Sets the path to the client certificate used to connect to the KMS. See Configure the KMS provider.

  • tde_kms_client_key: default empty. Sets the path to the private key of the client certificate. See Configure the KMS provider.

  • tde_kms_default_key_id: default empty. Specifies the KMS key identifier that wraps the tablespace data encryption key when CREATE TABLESPACE omits kms_key_id. See Configure the KMS provider.

  • tde_kms_command: default empty. Sets the shell command that the local_cmd provider runs to return a 256-bit key encryption key. See Configure the KMS provider.

  • tde_kms_connect_timeout: default 10 (s). Sets the timeout for connecting to the KMS. See Configure the KMS provider.

  • tde_kms_operation_timeout: default 30 (s). Sets the timeout for a single KMS operation. See Configure the KMS provider.

  • tde_max_tablespace_keys: default 128. Sets the maximum number of tablespace data encryption keys that a node caches in shared memory. See Encrypt a single tablespace.

  • datalake.iceberg_enable_predicate_pushdown: default on. Controls whether an Iceberg table scan uses predicate pushdown. See Configuration parameters.

  • datalake.iceberg_enable_batch_read: default on. Lets the Parquet reader decode and convert whole columns in batches. See Configuration parameters.

  • datalake.iceberg_enable_balanced_scan: default on. Distributes Iceberg scan tasks across segments by data file size so that each segment scans a similar number of bytes. See Configuration parameters.

  • datalake.iceberg_analyze_statistics_target: default 1000. Sets the minimum statistics target that ANALYZE uses when every target table is an Iceberg table. See Configuration parameters.

  • datalake.iceberg_analyze_snap_unique_ndv: default on. Keeps recording an almost-unique column of an Iceberg table as unique after the statistics target is raised. See Configuration parameters.

  • datalake_fdw.deletion_queue_enabled: default on. Enables the autovacuum-driven Iceberg deletion queue consumer, which cleans up pending data and metadata files in the background. See Configuration parameters.

  • datalake_fdw.deletion_queue_batch_size: default 100. Sets the maximum number of deletion queue entries processed per autovacuum cycle. See Configuration parameters.

  • datalake_fdw.deletion_queue_max_retry: default 5. Sets the retry limit for a deletion queue entry, after which the entry moves to the failed table. See Configuration parameters.

  • datalake_fdw.deletion_queue_min_interval: default 60 (s). Sets the minimum interval between two deletion queue consumer runs within the same autovacuum worker process. See Configuration parameters.

  • vector.enable_sonic_hashjoin: default off. Lets a vectorized hash join run on the Sonic join engine. See Configuration parameters.

  • vector.sonicagg_spill_memory_mb: default 512 (MB). Sets the memory budget for spilling the Sonic hash aggregate to disk. See Configuration parameters.

  • vector.enable_vec_pipeline: default off. Lets vectorized scan nodes use pipeline execution mode. See Configuration parameters.

  • vector.backpressure_memory_mb: default 256 (MB). Sets the memory budget for backpressure on each SinkNode queue. See Configuration parameters.

  • optimizer_enable_right_join_flip: default on. Lets GPORCA flip semi and anti hash joins into right semi and anti hash joins so that the hash table is built on the smaller side. See Configuration parameters.

  • optimizer_enable_scalar_subq_filter_pushdown: default off. Lets GPORCA rewrite a correlated scalar subquery that aggregates on the join key into a window aggregate over the join result, removing one aggregation and one join from the plan. See Configuration parameters.

  • pg_gophermeta.gopher_plasma_size_mb: default 0 (MB). Sets the footprint of the Plasma L1 read cache that the GopherMeta process keeps in shared memory. 0 disables the cache. See Configuration parameters.

Components

  • Upgrade Gopher to version v4.0.29 and iceberg-gopher to version 4.0.4, which brings in accumulated fixes such as SASL QOP negotiation and plasma initialization.

  • Upgrade DBCC to version v1.5.1.

Improvements

Data federation and lakehouse integration

  • When dlagent restarts or is briefly unavailable, datalake_fdw retries over a longer window, and the Hive catalog cache now expires by TTL and by connection information, which reduces query failures such as dlagent not ready.

  • Unified the entry point that parses Iceberg and gopher configuration in datalake_agent, and consolidated duplicate storage type names such as s3a and s3av2.

  • Added DEBUG-level logging for how OSS credentials travel between datalake_fdw and dlagent, so the log alone shows which layer loses a credential.

  • Removed reload4j from the hivesync JAR and blocked it from returning at build time, which eliminates a logging implementation conflict.

Query optimizer and executor

  • A vectorized hash join and hash aggregate can now run on the Sonic engine and spill to disk when memory runs short, so a join or an aggregation over large tables no longer fails outright under memory pressure. vector.enable_sonic_hashjoin controls this capability and defaults to off.

  • The optimizer can now produce right semi join and right anti join plans, which the row execution engine, GPORCA, and the vectorized execution engine all support, so a semi join or an anti join no longer needs a flipped join order or a fallback to a plain join.

  • The vectorized executor now handles the intermediate combine stage of MIN, MAX, SUM, COUNT, AVG, and STDDEV in a three-stage aggregation, so the middle step no longer falls back to row-based execution.

Storage and access methods

  • The TOAST of a PAX auxiliary table now follows the same namespace routing rules as heap and AO tables, and an invalid combination of compresslevel and compresstype is rejected at table creation instead of at run time.

Security

  • Addressed dependency vulnerabilities in the datalake Java modules by upgrading Netty, Jackson, ZooKeeper, and other components and switching to the slimmed-down Hudi modules, which clears about 31 high-severity issues from the dlagent dependency tree. The datalake and hive-connector builds now generate an SBOM, which keeps the dependency inventory auditable.

Bug fixes

Data federation and lakehouse integration

  • Fixed silent data loss where a CHAR(N) column in an Iceberg table lost its right-padding spaces and could read back as an empty string for the whole column, and removed the type mapping warning that every query printed.

  • Fixed unbounded memory growth on the coordinator and a per-statement writer leak on the executors when running INSERT in bulk against an Iceberg table. Memory use during a large load now stays stable.

  • Fixed a crash where an Iceberg scan on the inner side of a nested loop join was rescanned repeatedly, which brought down every segment at once and triggered cluster-level recovery.

  • CREATE TABLE ... USING iceberg and a table creation that omits the volume now fail at creation time instead of leaving behind a table that can neither be queried nor dropped.

  • Fixed a missing isAdjustedToUTC annotation on Parquet writes, which made external engines such as Spark read TIMESTAMPTZ values at the wrong time and lose the time zone.

  • Fixed quadratic growth of the fragment list of an Iceberg scan with the number of data files and delete files, which removes memory exhaustion and query cancellation under concurrent UPDATE.

  • Fixed permanent leftovers of the metadata, manifest, and snapshot files written by a transaction that later runs ROLLBACK.

  • Fixed a false error from gopherCloseFile and a file handle leak when a scan ends early. Multiple slices of one query that read the same fragment concurrently no longer fail.

  • Fixed a crash where pg_gophermeta exited when the shared memory size was uninitialized, which failed cluster initialization, left the coordinator in a crash-restart loop, and produced a large number of core files.

  • Added the missing gopher connection configuration to the Iceberg commit path and the datalake_fdw write path, which fixes writes that failed outright in some deployment shapes.

  • Fixed a URL rewrite that dlagent applied to the Iceberg HadoopCatalog, which no longer diverges from the real HDFS address.

  • The Hive catalog cache now expires when a connection fails, so a brief Hive Metastore outage no longer requires a database restart to recover from.

  • Pinned the endpoint region for s3 and hadoop Iceberg catalogs, which fixes queries that hung for a long time during region discovery.

  • Fixed a dropped gopher configuration on the dlproxy read path, which made queries against an Iceberg foreign table report Failed to initialize GopherFileIO.

  • Fixed Unrecognized hdfs name node when creating an Iceberg table with an HDFS volume specified through inline OPTIONS.

  • Fixed a runtime NoClassDefFoundError in hivesync caused by a missing provider for the log4j 1.x API.

  • The encoding option of an FDW now accepts an encoding name such as UTF8 in addition to a numeric encoding ID.

Query optimizer and executor

  • Fixed several correctness defects in GPORCA. In one of them, the ON predicate of a left outer join was pushed down to its own outer side, which made a query silently return fewer rows. The rest cover a use-after-free in a window function rewrite, an assertion failure on an empty partition, skip-level correlated subqueries, and direct dispatch.

  • Fixed wrong results and crashes from parallel execution in the presence of replicated tables, parallel CTEs, a subquery LIMIT, and parallel bitmap scans on AO, AOCO, and PAX tables.

  • Fixed wrong results from an ordered-set aggregate under parallel execution, and made a standalone sort that feeds a GroupAggregate directly spill to disk on large inputs so that it no longer fails in memory.

  • Fixed a crash in the vectorized window hash aggregate on an empty partition and an InitPlan parameter that a vectorized expression on the coordinator froze to 0, and upgraded Arrow to fix the huge number of spill files from the Sonic aggregate that hung queries for a long time.

  • Fixed an error from a ShareInputScan that crosses slices under vectorized execution and abnormal rescan behavior under parallel scan, which restores queries that reuse a CTE.

  • Fixed a crash from incorrect barrier use in the parallel hash join on aarch64.

  • Fixed a use-after-free on the path that retrieves the name of an extended statistics object.

Storage and access methods

  • Fixed a missing command counter increment before AO table VACUUM truncation, a stack overflow from passing PAX exception objects by value, a missing concurrent index build check on AO and PAX tables, and a REINDEX that did not revalidate partition indexes.

Processes and concurrency

  • Fixed a combocid assertion that ended a reader process (QE_READER) with FATAL.

Security

  • Iceberg object names are now encoded correctly or rejected, which fixes a path injection risk where a table name containing #, ?, or / was truncated and the request landed on a different table.

Tools and utilities

  • Fixed a gpupgrade failure at the execute stage that reported found xmin ... before relfrozenxid, and false wraparound warnings after the upgrade where running VACUUM and then VACUUM (FREEZE) on a partitioned table hung permanently and stalled VACUUM and DDL across the database.

  • Fixed a failure at the finalize stage when upgrading a cluster with mirrors in link mode. UNLOGGED tables have no data files on the mirrors, so link mode still tried to hard-link them, and the upgrade could no longer be reverted at that point.

  • Cleaned up event trigger dependency records that an older version wrote incorrectly and that the upgrade carried over to the segments, which fixes DROP FUNCTION reporting a dependency on the segments after DROP EVENT TRIGGER.

  • Fixed 'SyncPackages' object has no attribute 'ret' in gppkg operations.

  • pg_basebackup now checks for the replication slot and creates it when needed beforehand, so segment recovery no longer runs a full base backup only to fail at the end because the slot does not exist.

Observability

  • Fixed gpsmon logs landing in $HOME rather than under gpperfmon/logs in the data directory. The directory is now created recursively when needed, and a fallback raises a warning.

  • Fixed gpsmon spinning and saturating one CPU core when the peer closed the connection early during the HELLO handshake.

  • Fixed an incorrect index space calculation in the gp_get_suboverflowed_backends view, which returned wrong data.

  • Fixed a PARALLEL RETRIEVE CURSOR check timeout that kept raising warnings.