Re: Possible command-injection or meta-command execution in `psql` input - Mailing list pgsql-docs

From David G. Johnston
Subject Re: Possible command-injection or meta-command execution in `psql` input
Date
Msg-id CAKFQuwbpNYxCy2GOkkkpADRT9dt2+rYS7knBi1biedi_tYwXCA@mail.gmail.com
Whole thread
In response to Possible command-injection or meta-command execution in `psql` input  (PG Doc comments form <noreply@postgresql.org>)
List pgsql-docs
On Saturday, September 26, 2026, PG Doc comments form <noreply@postgresql.org> wrote:
The following documentation comment has been logged on the website:

Page: https://www.postgresql.org/docs/18/index.html
Description:

AI generated ))

## Summary

The following SQL statement contains an unquoted regular-expression-like
expression:

This is the wrong place to get help with using PostgreSQL or to report bugs.

I don’t really care if you use AI to help write such a report - but this particular one seems excessively long and repetitive.  I’d also be a bit surprised if AI couldn’t explain why you see the behavior that you do.

And hopefully AI would tell you that if you write SQL with syntax errors there is usually no predicable way to know exactly what the failure mode will look like nor is there usually much desire to try and control it.  This is why you have to test the code that you write; making sure at minimum the happy path is functioning.  You have to trust the people who can send SQL to your server.  You can limit their rights but just connecting gives a decent amount of ability to cause grief.  These are not security issues.

David J.

pgsql-docs by date:

Previous
From: PG Doc comments form
Date:
Subject: [Minor] Wording in "2.2. Concepts"
Next
From: PG Doc comments form
Date:
Subject: [Minor] Conflicting sentence in "2.4. Populating a Table With Rows"