fix(vector): verify writer sequence privileges
This commit is contained in:
@@ -73,3 +73,23 @@ Fresh verification after the fix wave:
|
||||
- Expanded focused adapter/config suite: `56 passed`.
|
||||
- Full harness: `466 passed, 5 deselected`.
|
||||
- Changed-file Ruff lint/format and `git diff --check`: clean.
|
||||
|
||||
## Sequence privilege health follow-up
|
||||
|
||||
Writer health now resolves the real serial/identity sequence for the `id` column of every
|
||||
required collection using `pg_get_serial_sequence`. It requires `USAGE` on each resolved
|
||||
sequence, which is the privilege used by the adapter's implicit `nextval`; sequence `SELECT` is
|
||||
not required because no adapter operation reads sequence state.
|
||||
|
||||
The Docker fixture includes a writer role with complete table/hash-column authority but no
|
||||
sequence grant. Its health is deterministically unhealthy and a new-key upsert fails. Granting
|
||||
only sequence `USAGE` makes health green and the same port upsert succeeds. Sequence discovery is
|
||||
guarded for partial schemas so a missing `id` column produces the existing sanitized schema
|
||||
diagnostic instead of a PostgreSQL error.
|
||||
|
||||
Fresh verification for this follow-up:
|
||||
|
||||
- Docker pgvector L0 after formatting: `17 passed`.
|
||||
- Expanded focused adapter/config/parity suite: `57 passed`.
|
||||
- Full harness: `467 passed, 5 deselected`.
|
||||
- Changed-file Ruff lint/format and `git diff --check`: clean.
|
||||
|
||||
Reference in New Issue
Block a user