Re: Possible command-injection or meta-command execution in `psql` input

From: "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>
To: "y(dot)saburov(at)gmail(dot)com" <y(dot)saburov(at)gmail(dot)com>, "pgsql-docs(at)lists(dot)postgresql(dot)org" <pgsql-docs(at)lists(dot)postgresql(dot)org>
Subject: Re: Possible command-injection or meta-command execution in `psql` input
Date: 2026-09-28 15:02:12
Message-ID: CAKFQuwbpNYxCy2GOkkkpADRT9dt2+rYS7knBi1biedi_tYwXCA@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-docs

On Saturday, September 26, 2026, PG Doc comments form <
noreply(at)postgresql(dot)org> wrote:

> The following documentation comment has been logged on the website:
>
> Page: https://www.postgresql.org/docs/18/index.html
> Description:
>
> AI generated ))
>
> ## Summary
>
> The following SQL statement contains an unquoted regular-expression-like
> expression:

This is the wrong place to get help with using PostgreSQL or to report bugs.

I don’t really care if you use AI to help write such a report - but this
particular one seems excessively long and repetitive. I’d also be a bit
surprised if AI couldn’t explain why you see the behavior that you do.

And hopefully AI would tell you that if you write SQL with syntax errors
there is usually no predicable way to know exactly what the failure mode
will look like nor is there usually much desire to try and control it.
This is why you have to test the code that you write; making sure at
minimum the happy path is functioning. You have to trust the people who
can send SQL to your server. You can limit their rights but just
connecting gives a decent amount of ability to cause grief. These are not
security issues.

David J.

In response to

Browse pgsql-docs by date

  From Date Subject
Next Message PG Doc comments form 2026-09-28 15:04:28 [Minor] Conflicting sentence in "2.4. Populating a Table With Rows"
Previous Message PG Doc comments form 2026-09-28 14:42:55 [Minor] Wording in "2.2. Concepts"