Contents
Changelog
Versions are released on PGXN. Each
upgrade script (pg_promise_guard--OLD--NEW.sql) documents, in its own header,
exactly what changed and why; that is the authoritative per-version record.
0.2.7 – 2026-10-09
- The scanner reads the real catalog, whatever schema the extension lives in (PG-01,
external audit of 0.2.5). Every function searched its own schema before
pg_catalog. In an installation that began at 0.1.0 that schema ispublic, and a role allowed to create there – the default before PostgreSQL 15 – added emptypublic.pg_triggerandpublic.pg_index:check_promises()found nothing,promises_kept()said true, and the watched assertion recordedholdsover a disabled trigger (measured on 0.2.6,test/desde_010.sh). Every function now searchespg_catalogfirst;watch()qualifies what its check calls and declares it under that path. Watches declared before 0.2.7 keep their old path: the upgrade names them, and retiring and watching again moves them.
0.2.6 – 2026-10-08
- Metadata only. The PGXN description is two sentences now; the longer explanation it carried is in this README. No code changed: the upgrade script 0.2.5 -> 0.2.6 changes no object.
0.2.5 – 2026-10-08
- An installation that began at 0.1.0 can upgrade, and its
watch()works. 0.1.0 fixed no schema, so it was installed wherever the caller said – usuallypublic; 0.2.0 fixedschema = promise_guardfor new installations only. The 0.2.3 -> 0.2.4 script namedpromise_guardliterally and failed there withschema "promise_guard" does not exist(found upgrading a real database; the failure was all or nothing). The script now says@extschema@, as the 0.1.0 -> 0.2.0 script always did.watch()is recreated naming the schema the extension is in: the published 0.2.0 already did, and this normalizes awatch()from a pre-release build that namedpromise_guardliterally.test/desde_010.sh(make check-desde-010) reproduces the origin – 0.1.0 installed with its own control file, then updated – whichci/upgrade_check.shcannot, since it installs every old version with the current control file.
0.2.4 – 2026-10-08
- A temporary table of the session that evaluates a promise can no longer hide
a broken one.
check_promises()reads the catalog without a schema undersearch_path = promise_guard, pg_catalog, and PostgreSQL searches an unnamedpg_tempfirst for tables: a temporarypg_triggerorpg_classstood in for the real catalog. That matters when the evaluation runs in someone else’s session with the owner’s rights – aSECURITY DEFINERfunction that runs the assertionwatch()declared, as pg_agent_gate does inside an agent’s commit. Measured on 0.2.3 (test/pg_temp.sh,make check-pgtemp): a disabled audit trigger readbroken, andholdsonce the evaluating session kept an emptypg_temp.pg_triggerorpg_temp.pg_class. Every function now namespg_templast. No table changes.
0.2.3 – 2026-10-06
- License: Apache License 2.0, replacing the PostgreSQL License, from this release on. Every version up to and including 0.2.2, already published, stays under the PostgreSQL License it was released with. No code changed.
0.2.2
Completes the copyright and licensing files: the copyright holder’s full legal name in LICENSE and README, and a per-file SPDX header on every SQL source file. No schema change.
0.2.1
No schema change. Adds project governance and legal files (NOTICE, AUTHORS,
SECURITY, CONTRIBUTING, TRADEMARK). The database objects are byte-for-byte those
of 0.2.0; the 0.2.0--0.2.1 upgrade is empty on purpose.
0.2.0 and earlier
See the header of each pg_promise_guard--*--*.sql upgrade script and the
release notes on PGXN.