jackc/pgx · error

invalid arg type: %T

Error message

invalid arg type: %T

What it means

Sanitize only supports a fixed set of Go types for inlining into SQL (nil, int64, float64, bool, []byte, string, time.Time). An argument of any other type triggers this guard because it cannot be safely rendered into the sanitized query.

Solutions

  1. Convert the argument to one of the supported types before sanitizing
  2. For custom types, implement conversion to string or []byte first
  3. Use parameterized queries instead of sanitization for unsupported types
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at internal/sanitize/sanitize.go:87 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/bb6520aea651dcd8. Report an issue: GitHub.

Appendix: source

Thrown at internal/sanitize/sanitize.go:87

			arg := args[argIdx]
			switch arg := arg.(type) {
			case nil:
				p = null
			case int64:
				p = strconv.AppendInt(buf.AvailableBuffer(), arg, 10)
			case float64:
				p = strconv.AppendFloat(buf.AvailableBuffer(), arg, 'f', -1, 64)
			case bool:
				p = strconv.AppendBool(buf.AvailableBuffer(), arg)
			case []byte:
				p = QuoteBytes(buf.AvailableBuffer(), arg)
			case string:
				p = QuoteString(buf.AvailableBuffer(), arg)
			case time.Time:
				p = arg.Truncate(time.Microsecond).
					AppendFormat(buf.AvailableBuffer(), "'2006-01-02 15:04:05.999999999Z07:00:00'")
			default:
				return "", fmt.Errorf("invalid arg type: %T", arg)
			}
			argUse[argIdx] = true

			buf.Write(p)

			// Prevent SQL injection via Line Comment Creation
			// https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p
			buf.WriteByte(' ')
		default:
			return "", fmt.Errorf("invalid Part type: %T", part)
		}
	}

	for i, used := range argUse {
		if !used {
			return "", fmt.Errorf("unused argument: %d", i)
		}
	}

View on GitHub (pinned to ec1a0befd2)