BUG #19682: Unable to drop a user with default privileges revoked

From: PG Bug reporting form <noreply(at)postgresql(dot)org>
To: pgsql-bugs(at)lists(dot)postgresql(dot)org
Cc: ext(dot)solutec(dot)sperraud(at)grandlyon(dot)com
Subject: BUG #19682: Unable to drop a user with default privileges revoked
Date: 2026-09-09 09:29:50
Message-ID: 19682-21342a50fcf153e5@postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

The following bug has been logged on the website:

Bug reference: 19682
Logged by: Sylvain Perraud
Email address: ext(dot)solutec(dot)sperraud(at)grandlyon(dot)com
PostgreSQL version: 18.4
Operating system: RHEL 9.8
Description:

Hello,

Scenario 1 : create a user alpha then grant default privileges to himself

test=# create user alpha;
CREATE ROLE
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)

test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)

test=# drop user alpha;
DROP ROLE

Conclusion 1 : Drop is working

***********************************************************************************************************************************************************************************
Scenario 2 : create a user alpha then revoke default privileges from himself
test=# create user alpha;
CREATE ROLE
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha REVOKE ALL ON TABLES FROM
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+-------------------
alpha | | table | (none)
(1 row)

test=# drop user alpha;
ERROR: role "alpha" cannot be dropped because some objects depend on it
DETAIL: owner of default privileges on new relations belonging to role
alpha

Conclusion 2 : Drop is not working
***********************************************************************************************************************************************************************************
Scenario 3 : create a user alpha and beta then grant default privileges to
both users
test=# create user alpha;
CREATE ROLE
test=# create user beta;
CREATE ROLE
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to beta;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+---------------------
alpha | | table | beta=arwdDxtm/alpha
(1 row)

test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+----------------------
alpha | | table | alpha=arwdDxtm/alpha+
| | | beta=arwdDxtm/alpha
(1 row)

test=# drop user alpha;
ERROR: role "alpha" cannot be dropped because some objects depend on it
DETAIL: owner of default privileges on new relations belonging to role
alpha

test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha REVOKE ALL ON TABLES FROM
beta;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)

test=# drop user alpha;
DROP ROLE

Conclusion 3 : Drop is working whereas DEFAULT PRIVILEGES are still granted
to alpha

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Andrey Borodin 2026-09-09 09:59:14 Re: BUG #19664: nbtree: Assertion failure when a custom index AM reuses bthandler
Previous Message Luguoqing 2026-09-09 07:27:06 Re: table_rewrite event trigger can corrupt rows by inserting into the table being rewritten (20devel)