BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser

From: PG Bug reporting form <noreply(at)postgresql(dot)org>
To: pgsql-bugs(at)lists(dot)postgresql(dot)org
Cc: theshallow27(at)gmail(dot)com
Subject: BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser
Date: 2026-10-02 22:38:00
Message-ID: 19740-677922f8a0cc921c@postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

The following bug has been logged on the website:

Bug reference: 19740
Logged by: Shallow
Email address: theshallow27(at)gmail(dot)com
PostgreSQL version: 18.6
Operating system: Linux
Description:

For a nonexistent language OID, the implicit-current-user form returns TRUE
when the current user is a superuser. An explicit non-superuser role returns
NULL for the same missing OID. This makes the result depend on the role's
superuser status even though the referenced language does not exist.

**Reproduction:** Run as the default `postgres` superuser:

```sql
SELECT NOT EXISTS (SELECT FROM pg_language WHERE oid = 0),
has_language_privilege(0::oid, 'USAGE'),
has_language_privilege('pg_monitor', 0::oid, 'USAGE');
```

**Actual result:** `true | true | NULL`.

**Expected result:** The privilege inquiry should return NULL for the
missing
language OID in both forms, matching the function's missing-object handling
for non-superuser roles.

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message PG Bug reporting form 2026-10-02 22:38:39 BUG #19741: `avg(double precision)` overflows on cancelling finite inputs whose mean is representable
Previous Message PG Bug reporting form 2026-10-02 22:37:31 BUG #19739: Parameterized first autocommit statement can have different `transaction_timestamp()` and `statement