Repository navigation
Apply the sensitive-statement filter to collected PostgreSQL statement text (#4348) - #4383
Merged
Merged
Conversation
The corpus (#4348) found ALTER ROLE app SET work_mem = '64MB' flagged as sensitive. Its first alternative matched CREATE|ALTER ROLE|USER|GROUP| SUBSCRIPTION|SERVER by name alone, meaning to catch every credential- bearing form of that DDL, but every such form already ends in a literal that the remaining alternatives catch, so the blanket alternative added false positives and nothing else. Removed; verified against the corpus plus the existing StoreStatementStatsLiveTests cases on a scratch PostgreSQL 18 container.
…4348) PgStatementTextScrubLiveTests seeds matching and neighbor rows in both collect.pg_statement_text and a compressed collect.pg_blocking_edges chunk for two servers, runs PgStatementTextScrub.RunAsync, and checks matching rows became the placeholder, neighbors are untouched, the marker equals ScrubVersion, and a second run changes 0 rows. Also rephrases two comments in PgStatementTextScrub.cs to a neutral current-state wording.
…word option forms (#4348)
…live-postgres collection
…in the built SQL against it
…LSTATE, not its message text
erikdarlingdata
marked this pull request as ready for review
September 26, 2026 04:48
erikdarlingdata
deleted the
fix/4348-collected-statement-text-filter
branch
September 26, 2026 04:48
erikdarlingdata
added a commit
that referenced
this pull request
Sep 26, 2026
…33Z UTC (#4440) Moves the CHANGELOG entries carried in merged pull-request descriptions into [Unreleased]. The cut is PRs merged at or before 2026-09-26T17:37:33Z; the next splice starts after it. - 128 PRs are spliced: Fixed 87, Changed 20, Added 17 and Security 5. Each entry sits at the top of its section, newest PR first, and its link definition joins the trailing block. - 22 PRs have no user-visible entry (None, test-only, or deferred to a parent). - Three entries had no section in their description, and each was assigned from its diff: #4363, #4383 and #4380 go under Security. - Link fixes: the #4198 references point at the issue, and #4360's [#4203] label points at issue 4203. - #4208's entry is taken from its diff. - Two security entries are worded to the current state: #4351's rotation note, and #4363's journal-read line. - Only CHANGELOG.md changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #4348.
Collected PostgreSQL statement text now goes through the same sensitive-statement filter the store already applies to its own statements:
PgSensitiveStatementFilterholds the one pattern definition.StoreStatementStatsuses it, and so do the two collectors that store statement text from a monitored server (PgStatementTextandPgBlockingCollector).CHANGELOG entry