jackc/pgx · error

EscapeString must be run with standard_conforming_strings=on

Error message

EscapeString must be run with standard_conforming_strings=on

What it means

EscapeString guard: the connection's standard_conforming_strings server parameter is not 'on'. EscapeString's escaping algorithm is only correct when backslashes are not literal escape characters in string literals, so it refuses to run rather than produce unsafe SQL.

Solutions

  1. Set standard_conforming_strings=on in postgresql.conf (the default since PostgreSQL 9.1)
  2. Prefer parameterized queries or the pgtype text codec over manual string escaping
Defensive patterns

Strategy: try-catch

When it happens

Trigger: Thrown at pgconn/pgconn.go:2069 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/8b927dc60161bc71. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/pgconn.go:2069

	if err != nil {
		pgConn.contextWatcher.Unwatch()
		multiResult.err = normalizeTimeoutError(multiResult.ctx, err)
		multiResult.closed = true
		pgConn.asyncClose()
		return multiResult
	}

	return multiResult
}

// EscapeString escapes a string such that it can safely be interpolated into a SQL command string. It does not include
// the surrounding single quotes.
//
// The current implementation requires that standard_conforming_strings=on and client_encoding="UTF8". If these
// conditions are not met an error will be returned. It is possible these restrictions will be lifted in the future.
func (pgConn *PgConn) EscapeString(s string) (string, error) {
	if pgConn.ParameterStatus("standard_conforming_strings") != "on" {
		return "", errors.New("EscapeString must be run with standard_conforming_strings=on")
	}

	if pgConn.ParameterStatus("client_encoding") != "UTF8" {
		return "", errors.New("EscapeString must be run with client_encoding=UTF8")
	}

	return strings.ReplaceAll(s, "'", "''"), nil
}

// CheckConn checks the underlying connection without writing any bytes. This is currently implemented by doing a read
// with a very short deadline. This can be useful because a TCP connection can be broken such that a write will appear
// to succeed even though it will never actually reach the server. Reading immediately before a write will detect this
// condition. If this is done immediately before sending a query it reduces the chances a query will be sent that fails
// without the client knowing whether the server received it or not.
//
// Deprecated: CheckConn is deprecated in favor of Ping. CheckConn cannot detect all types of broken connections where
// the write would still appear to succeed. Prefer Ping unless on a high latency connection.
func (pgConn *PgConn) CheckConn() error {

View on GitHub (pinned to ec1a0befd2)