Incident brief
Invalid XML comment
xmlcomment() rejects text that would produce an illegal XML comment — XML comments cannot contain a double hyphen or end with a hyphen.
In 10 seconds
- What
- Invalid XML comment
- What triggers it
- Call xmlcomment(text) with text that contains '--' or ends with '-'.
- The fix
- Remove or replace '--' sequences (and any trailing '-') in the comment text.
- Proof
- Reproduced on PostgreSQL 18.4 → A single SELECT reproduces SQLSTATE 2200S; the illegal comment text is rejected by xmlcomment().
The fix
What to do right now
The immediate, application-level response to this error.
- Remove or replace '--' sequences (and any trailing '-') in the comment text.
- Sanitize interpolated text before wrapping it in xmlcomment().
-- XML comments cannot contain '--' or end with '-'.
SELECT xmlcomment('build failed');Diagnose
See it live on the server
Run these against the affected instance to confirm the diagnosis before you act.
Standard triage — not specific to this error
These are canonical PostgreSQL system-catalog queries, shown as SQL to run. No sample output is attached because this is general triage, not a captured lab transcript.This SQLSTATE does not have an error-specific live snapshot yet. These are the canonical system-catalog queries you run against the affected server to see the problem in real time — standard triage, not a reproduced transcript.
What is running right now
Active backends, how long each has been running, and what it is waiting on.
SELECT pid,
state,
wait_event_type,
wait_event,
now() - query_start AS running_for,
left(query, 80) AS query
FROM pg_stat_activity
WHERE state <> 'idle'
AND pid <> pg_backend_pid()
ORDER BY running_for DESC NULLS LAST;Who is blocking whom
Turn raw blocking PIDs into the actual queries on both sides of the wait.
SELECT blocked.pid AS blocked_pid,
blocked.query AS blocked_query,
blocking.pid AS blocking_pid,
blocking.query AS blocking_query
FROM pg_stat_activity AS blocked
JOIN LATERAL unnest(pg_blocking_pids(blocked.pid)) AS b(pid) ON true
JOIN pg_stat_activity AS blocking ON blocking.pid = b.pid
WHERE cardinality(pg_blocking_pids(blocked.pid)) > 0;Locks that are still waiting
Every lock a backend has requested but not yet been granted.
SELECT l.pid,
l.locktype,
l.mode,
l.granted,
COALESCE(c.relname, l.transactionid::text) AS object
FROM pg_locks l
LEFT JOIN pg_class c ON c.oid = l.relation
WHERE NOT l.granted
ORDER BY l.pid;Why it happens
What PostgreSQL is telling you
The mechanism behind the error, grounded in the official manual — not paraphrased.
PostgreSQL 18 Documentation — Appendix A. PostgreSQL Error Codes (Table A.1, Class 22 — Data Exception)
2200S → invalid_xml_commentRead the full section on postgresql.org →
Building an illegal XML comment
XML forbids '--' inside a comment, so xmlcomment() on such text raises 'invalid XML comment'.The session continues normally
The failing statement ran outside a transaction block, so nothing was left in a bad state — the next statement in the same connection runs normally.Reproduce & verify
A real, single-session PostgreSQL reproduction
A literal transcript of SQL run against a live PostgreSQL instance in an isolated lab — the commands below are exactly what was executed.
- 1Call xmlcomment(text) with text that contains '--' or ends with '-'.
- 2PostgreSQL checks that the resulting comment would be legal XML.
- 3The illegal comment aborts the statement with SQLSTATE 2200S.
A build note containing a double hyphen was pushed into an XML comment and broke the document generation.
-- The error is self-contained in one statement; no schema is required.
SELECT 'no schema needed' AS setup_note;SELECT xmlcomment('build--failed');SELECT 'ok' AS session_after_error;What PostgreSQL actually returned
setup_note
------------------
no schema needed
(1 row)ERROR: invalid XML comment session_after_error
---------------------
ok
(1 row)xmlcomment() succeeds once the text is a legal comment body.
We call xmlcomment() with clean text to show the comment it produces.
Without this
Before: '--' in the text aborts
With this, tested
After: clean text produces a comment
What Pro unlocks here
- The exact prevention SQL — copy-paste ready
- Raw psql output captured from the Docker lab
- A senior-DBA action list to take it further
- Live monitoring queries to catch it in production
- The deeper audit: fix-that-fails counterexample, GUC before/after, server-log evidence
Related & next steps
Follow the thread
Everything this error touches — jump straight to the sibling error, term, runbook, or parameter.
Verification
- Last verified
- 2026-07-24 (isolated lab, PostgreSQL 18.4)
- Reviewed by
- Verified against PostgreSQL 18.4 in an isolated lab environment
- Audit status
- reviewed