postgresql-pg-vault-tde (1.7.2-1) unstable; urgency=medium * Fix: INSERT, COPY, UPDATE, UPSERT and the VACUUM FULL / CLUSTER rewrite crashed the backend (SIGSEGV in toast_save_datum) for values whose tuple crossed TOAST_TUPLE_THRESHOLD only once encrypted. The pre-TOAST gate tested the plaintext length while heap_prepare_insert re-tests the encrypted one, leaving a window as wide as the AES-GCM overhead in which PostgreSQL tried to TOAST opaque ciphertext. The gate now tests the encrypted length and the TOAST writer reserves TDE_V4_OVERHEAD in its target, so the guarantee holds end to end. A 2000-byte STORAGE EXTERNAL value crashed while 1995 and 2005 did not, which is why this survived until a boundary sweep looked for it. * Fix: the server failed to start when built with --enable-cassert. _PG_init called GetUserId() to test its own validity, but that function opens with Assert(OidIsValid(CurrentUserId)) and no session user exists during process_shared_preload_libraries(). Packagers and anyone testing on an assert-enabled build could not load the extension at all. * Fix: ten catalog scans passed an unregistered snapshot to systable_beginscan(). Nothing pinned it for the life of the scan, and an assert-enabled server rejected it outright on ordinary CREATE TABLE. * Fix: three try_relation_open() calls used NoLock without holding a lock, so the relation could be dropped underneath them. * Fix: hint bits were written during the CLUSTER rewrite without the buffer content lock. * Fix: freeze decisions during VACUUM FULL / CLUSTER read uninitialised fields of struct VacuumCutoffs. The call was also redundant -- rewrite_heap_tuple() already freezes with correctly sourced cutoffs -- and has been removed. * Fix: locals read by PG_CATCH after a longjmp were missing volatile, so their cleanup was skipped on the error path, including an OPENSSL_cleanse() of decrypted tuple data. * Fix: the source tarball used for packaging no longer picks up the tmp_* scratch directories left by the test stages. Some hold files written under a container uid that the packaging build cannot read, which aborted the build rather than merely enlarging the tarball. * No SQL or catalog change: pg_extension.extversion stays at 1.7. Use pg_vault_tde_build_version() to tell 1.7.2 from 1.7.1 and 1.7.0 at runtime. -- Miriade S.r.l. Sat, 19 Sep 2026 13:02:25 +0200 postgresql-pg-vault-tde (1.7.1-1) unstable; urgency=medium * Fix: ALTER TABLE ... SET ACCESS METHOD encrypted_heap on a table that already contained rows failed with "AES-256-GCM authentication FAILED". The AEAD associated data is now derived from the effective relation OID (resolve_effective_relid), i.e. the same OID the DEK and the generation counter were already being looked up under. * Fix: CREATE TABLE AS / INSERT ... SELECT from an encrypted_heap table holding out-of-line TOAST values copied a dangling TOAST pointer instead of the value, leaving the destination unreadable once the source table was dropped. HEAP_HASEXTERNAL is now recomputed on every decrypted tuple instead of being inherited from the on-disk header. * Decrypt failures on a relation whose AEAD tag is bound to a different OID now carry a DETAIL/HINT naming the 1.7.0 -> 1.7.1 change, so the bare "data integrity violation" no longer sends operators into disaster recovery for what is a reversible version mismatch. * No SQL changes: pg_extension.extversion stays at 1.7. Use pg_vault_tde_build_version() to tell 1.7.1 from 1.7.0 at runtime. * 140 regression tests passing (52 v1.4 + 20 v1.5 + 38 v1.6 + 30 v1.7). * UPGRADE NOTE: with pg_vault_tde.toast_encryption = on (the default), out-of-line TOAST values written by 1.7.0 or earlier do not authenticate under this release, and pg_dump of an affected table fails. Everything else — non-TOAST tables, inline values, non-TOASTed columns — is read back byte-identical. Nothing is lost and reinstalling 1.7.0 restores access, but the export must be taken BEFORE this package is installed. See "Upgrading to 1.7.1" in README.md for the preflight query and the dump/restore procedure. * COMPATIBILITY NOTE (not a change in this release): PostgreSQL 17.11, 18.x and the matching minors of the older back branches only load a library named as a logical decoding output plugin if it is listed in the output_plugin_libraries GUC (default "pgoutput, test_decoding"). Slot creation otherwise fails with 'library "pg_vault_tde" may not be used as an output plugin'. Publishers replicating encrypted_heap tables need output_plugin_libraries = 'pgoutput, pg_vault_tde' in postgresql.conf and a reload. Earlier minors have no such GUC and must not carry the line. -- Miriade S.r.l. Sat, 05 Sep 2026 00:00:00 +0200 postgresql-pg-vault-tde (1.7-1) unstable; urgency=medium * v1.7: tde_btree access method — encrypted (AES-256-SIV) index keys for bytea/text/int4/int8/numeric/uuid/date/timestamptz operator classes; index-only scans disabled by design. * KEK/DEK wrapping hierarchy: provider-agnostic wrap_dek/unwrap_dek/ rewrap_dek API; wrapped_dek is now the authoritative catalog column for every KMS provider (Vault, wallet, PKCS#11). * PKCS#11/HSM KMS provider: direct Cryptoki wrap/unwrap of DEKs (CKM_AES_KEY_WRAP), versioned KEK objects, cross-backend rotation propagation via shared memory. CI covered with SoftHSM2. * Logical replication of encrypted_heap TOAST columns via a custom WAL resource manager (pg_vault_tde.toast_custom_rmgr, off by default). * Structured audit event logging (16 event types: DEK/KEK lifecycle, wallet open/close, relation encrypt/decrypt, access denied, etc.) to the server log for PCI-DSS/HIPAA trails. * Physical backup key handling: pg_vault_tde_seal_keys()/unseal_keys(), pg_basebackup_tde wrapper, and pg_restore_tde decrypt-and-pipe restore. * All KMS GUCs promoted to PGC_SUSET for per-database KMS configuration via ALTER DATABASE SET. * 137 regression tests passing (52 v1.4 + 20 v1.5 + 38 v1.6 + 27 v1.7). -- Miriade S.r.l. Mon, 08 Jun 2026 00:00:00 +0100 postgresql-pg-vault-tde (1.6-1) unstable; urgency=medium * v1.6: Local PKCS#12 wallet KMS provider (offline/air-gapped support). * Flexible passphrase sources: env var, file, command, dev_mode. * wallet_unlock/lock/rotate_kek/export_bundle/import_bundle SQL functions. * Online Vault-to-wallet migration (pg_vault_tde_migrate_vault_to_wallet). * Support for PostgreSQL 17 and 18 from a single source package. * 72 regression tests passing. -- Miriade S.r.l. Tue, 04 Mar 2026 00:00:00 +0100 postgresql-pg-vault-tde (1.0-1) unstable; urgency=medium * Initial release. * AES-256-GCM transparent encryption via Table Access Method API. * Support for PostgreSQL 18. * All 24 regression tests pass, including page-checksum compatibility. -- Miriade S.r.l. Fri, 27 Feb 2026 00:00:00 +0100