Copilot commented on code in PR #2497:
URL: https://github.com/apache/age/pull/2497#discussion_r3715445984
##########
regress/sql/security.sql:
##########
@@ -1449,3 +1449,37 @@ DROP ROLE rls_admin;
-- Drop test graph
SELECT drop_graph('rls_graph', true);
+
+-- ============================================================================
+-- NON-SUPERUSER drop_label REGRESSION TEST
+--
+-- Regression test for object_ownercheck() argument order in
+-- range_var_callback_for_remove_relation(). A non-superuser that OWNS a
+-- graph/label previously failed drop_label() with "unrecognized class ID"
+-- because rel_oid was passed as the classid instead of RelationRelationId.
+-- ============================================================================
+
+DROP ROLE IF EXISTS age_nonsuper;
+CREATE ROLE age_nonsuper LOGIN NOSUPERUSER;
+
+-- create_graph() creates a new schema in the current database, so the role
+-- needs CREATE on the database; managing labels needs USAGE + CREATE on
+-- ag_catalog. Grant CREATE on whatever database the tests run in.
+SELECT format('GRANT CREATE ON DATABASE %I TO age_nonsuper',
current_database())
+\gexec
Review Comment:
Using `SELECT ... \\gexec` makes the regression output depend on the
database name (and on how psql echoes executed statements), which can make the
test more brittle across different regression harnesses/configurations.
Consider doing the dynamic GRANT inside a `DO $$ ... EXECUTE format(...) ...
$$;` block so the output is deterministic (e.g., just `DO`) while still
granting on `current_database()`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]