| From: | PG Bug reporting form <noreply(at)postgresql(dot)org> |
|---|---|
| To: | pgsql-bugs(at)lists(dot)postgresql(dot)org |
| Cc: | ext(dot)solutec(dot)sperraud(at)grandlyon(dot)com |
| Subject: | BUG #19682: Unable to drop a user with default privileges revoked |
| Date: | 2026-09-09 09:29:50 |
| Message-ID: | 19682-21342a50fcf153e5@postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-bugs |
The following bug has been logged on the website:
Bug reference: 19682
Logged by: Sylvain Perraud
Email address: ext(dot)solutec(dot)sperraud(at)grandlyon(dot)com
PostgreSQL version: 18.4
Operating system: RHEL 9.8
Description:
Hello,
Scenario 1 : create a user alpha then grant default privileges to himself
test=# create user alpha;
CREATE ROLE
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)
test=# drop user alpha;
DROP ROLE
Conclusion 1 : Drop is working
***********************************************************************************************************************************************************************************
Scenario 2 : create a user alpha then revoke default privileges from himself
test=# create user alpha;
CREATE ROLE
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha REVOKE ALL ON TABLES FROM
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+-------------------
alpha | | table | (none)
(1 row)
test=# drop user alpha;
ERROR: role "alpha" cannot be dropped because some objects depend on it
DETAIL: owner of default privileges on new relations belonging to role
alpha
Conclusion 2 : Drop is not working
***********************************************************************************************************************************************************************************
Scenario 3 : create a user alpha and beta then grant default privileges to
both users
test=# create user alpha;
CREATE ROLE
test=# create user beta;
CREATE ROLE
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to beta;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+---------------------
alpha | | table | beta=arwdDxtm/alpha
(1 row)
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha GRANT ALL ON TABLES to
alpha;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+-------+----------------------
alpha | | table | alpha=arwdDxtm/alpha+
| | | beta=arwdDxtm/alpha
(1 row)
test=# drop user alpha;
ERROR: role "alpha" cannot be dropped because some objects depend on it
DETAIL: owner of default privileges on new relations belonging to role
alpha
test=# ALTER DEFAULT PRIVILEGES FOR ROLE alpha REVOKE ALL ON TABLES FROM
beta;
ALTER DEFAULT PRIVILEGES
test=# \ddp alpha
Default access privileges
Owner | Schema | Type | Access privileges
-------+--------+------+-------------------
(0 rows)
test=# drop user alpha;
DROP ROLE
Conclusion 3 : Drop is working whereas DEFAULT PRIVILEGES are still granted
to alpha
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Andrey Borodin | 2026-09-09 09:59:14 | Re: BUG #19664: nbtree: Assertion failure when a custom index AM reuses bthandler |
| Previous Message | Luguoqing | 2026-09-09 07:27:06 | Re: table_rewrite event trigger can corrupt rows by inserting into the table being rewritten (20devel) |