/explain/wraparound

wraparound

With 2^31 usable xids, an unfrozen row can only age so far before comparisons would invert and committed data would appear to be from the future. Postgres defends in stages: warnings at 40M xids of headroom, then a hard stop (no new write transactions) at 3M. Recovery is a vacuum of the tables holding the oldest relfrozenxid, at whatever speed the neglected table allows; the public postmortems measure it in hours to days, and two of them ended by truncating rebuildable terabyte tables instead.

DEMO — xid age over 365 d, toy tablesame chart system as the report
2,147,483,647 (wraparound)freeze_max_age = 200,000,000
day 090180270365
autovacuum_freeze_max_age200,000,000
default 200,000,000 · max 2,000,000,000
xid consumption40.00 M/day
transactions per day, 1 M → 400 M
AGGRESSIVE VACUUM EVERY
5.0 d
RUNS PER YEAR
73.0
MARGIN TO SHUTDOWN
48.7 d
SEE ALSO
relfrozenxidautovacuum_freeze_max_agevacuum_failsafe_age← back to start
One alarm prevents all of it: max(age(datfrozenxid)) over the cluster, paged at 1B. Modern Postgres (14+) no longer requires single-user mode for recovery.
wraparound — robovac