Summary
Identifier validation in sshx sql rejects the value but never says what is allowed or why this particular value looks wrong. Two shapes observed on origin/main @ 1be5f1d:
$ sshx sql -h=prod-web --db='[REDACTED]' "SELECT 1"
sshx: SQL statement blocked: database name "[REDACTED]" contains unsupported characters # rc=255
$ sshx sql -h=prod-web --db='my db;drop' "SELECT 1"
sshx: SQL statement blocked: database name "my db;drop" contains unsupported characters # rc=255
Both are technically correct and safe (fail-closed, exit 255), but neither helps the caller fix the input:
- No allowed charset.
contains unsupported characters doesn't name the offending character or the accepted set ([A-Za-z0-9_.-]?). The caller has to guess-and-retry.
- No placeholder/redaction hint. The first value is the shape produced by client-side output redaction (
[REDACTED]-style placeholders) — an agent that copies a redacted Inventory/log value into --db gets a validation error that reads like sshx found dangerous characters, when the real story is "you passed a placeholder, not a real database name". That misdirected my own triage once (RAM-TA3 Tools/sshx-experience-log.md, 2026-09-27 entry).
Proposed
Enrich the rejection message, e.g.:
sshx: SQL statement blocked: database name "[REDACTED]" contains unsupported characters
allowed: [A-Za-z0-9_.-]
hint: the value looks like a redacted placeholder ([...]); pass the real database name
- Charset part: always print allowed set (and optionally the offending byte index).
- Placeholder part: heuristic on bracketed-uppercase /
[REDACTED]-like tokens → one-line hint. No behavior change: still fail-closed with rc=255.
Environment
- Built from
origin/main 1be5f1d (v0.19.0-1-g1be5f1d); identical message on installed v0.17.0.
- Related log entry: RAM-TA3
Tools/sshx-experience-log.md → 2026-09-27 "sshx run 内嵌 psql 被静默判为 blocked".
Summary
Identifier validation in
sshx sqlrejects the value but never says what is allowed or why this particular value looks wrong. Two shapes observed onorigin/main@1be5f1d:Both are technically correct and safe (fail-closed, exit 255), but neither helps the caller fix the input:
contains unsupported charactersdoesn't name the offending character or the accepted set ([A-Za-z0-9_.-]?). The caller has to guess-and-retry.[REDACTED]-style placeholders) — an agent that copies a redacted Inventory/log value into--dbgets a validation error that reads like sshx found dangerous characters, when the real story is "you passed a placeholder, not a real database name". That misdirected my own triage once (RAM-TA3Tools/sshx-experience-log.md, 2026-09-27 entry).Proposed
Enrich the rejection message, e.g.:
[REDACTED]-like tokens → one-line hint. No behavior change: still fail-closed with rc=255.Environment
origin/main1be5f1d(v0.19.0-1-g1be5f1d); identical message on installed v0.17.0.Tools/sshx-experience-log.md→ 2026-09-27 "sshx run内嵌 psql 被静默判为 blocked".