| From: | Laurenz Albe <laurenz(dot)albe(at)cybertec(dot)at> |
|---|---|
| To: | y(dot)saburov(at)gmail(dot)com, pgsql-docs(at)lists(dot)postgresql(dot)org |
| Subject: | Re: Possible command-injection or meta-command execution in `psql` input |
| Date: | 2026-09-28 12:51:30 |
| Message-ID: | fd897878c2324790143f5c4f4caa2b7388b88c68.camel@cybertec.at |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-docs |
On Sat, 2026-09-26 at 08:27 +0000, PG Doc comments form wrote:
> AI generated ))
Then please validate the generated stuff rather than creating
extra work.
> The following SQL statement contains an unquoted regular-expression-like
> expression:
>
> db=# WITH products (id, name, price, action) AS
> (
> VALUES
> (1, 'apple', 100, '...')
> , (2, 'banana', 200, '...')
> , (3, 'orange', 150, '...')
> , (4, 'potato', 80, '...')
> , (5, 'tomato', 120, '...')
> )
> SELECT
> p.id
> , p.name
> , p.price
> , p.action
> FROM products AS p
> WHERE regexp_like(p.action, ((?<!-)\d+))
> ;
>
> [the complaint is that you get a list of tables rather than a result]
There is no bug there. The statement is *not* a regular expression,
because the single quotes around the string literal are missing.
As a consequence, a metacommand (\d+) is executed. That "swallows"
the two closing parentheses, and psql prompts you to close the two
parentheses and end the statement. If you do that, you get the
syntax error you deserve.
In short: garbage in, garbage out. No bug.
Yours,
Laurenz Albe
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Matemática A3K | 2026-09-28 12:56:46 | Re: Possible command-injection or meta-command execution in `psql` input |
| Previous Message | Laurenz Albe | 2026-09-27 12:08:17 | Re: log_line_prefix and JSON log format |