Skip to content

Fix DROP USER ownership reassignment and wire version reset - #186

Merged
farhan-syah merged 3 commits into
mainfrom
fix/drop-user-valid-owner-reassignment
Jul 20, 2026
Merged

farhan-syah merged 3 commits into
mainfrom
fix/drop-user-valid-owner-reassignment

Conversation

@farhan-syah

Copy link
Copy Markdown
Member

Summary

Fix DROP USER to properly reassign all object ownership and revoke all grants when a user is dropped. Add database scoping to ownership tracking to correctly handle multi-database environments. Reset wire format version to 1 pre-1.0 since there are no deployed clusters to roll forward.

Key Changes

  • Ownership reassignment: DROP USER now reassigns ownership of all object types (collections, functions, procedures, triggers, materialized views, sequences, schedules, change streams, continuous aggregates) to the tenant admin, not just collections
  • Multi-database scoping: Add database_id to StoredOwner structure and WAL replay tombstone tracking to correctly isolate ownership by database
  • Recovery & repair: Add owner_rewrite.rs and ownership_fallback.rs for systematic ownership recovery during catalog integrity repair and DDL fallback paths
  • Wire format simplification: Reset WIRE_FORMAT_VERSION to 1 and remove now-dead TENANT_ADMIN_ATOMIC_VERSION gate; pre-1.0, all feature gates are unconditionally true or false within any formable cluster
  • Test expansion: Comprehensive regression coverage for DROP USER scenarios across multiple object types and databases

Technical Details

The core issue: pre-fix, DROP USER only reassigned collections it could derive from the user's grant targets. Objects like sequences or functions owned by the user but not directly in grants would be left with dangling owner references, causing catalog integrity checks to fail on the next boot with unrecoverable DanglingReference violations.

The fix introduces centralized ownership rewrite logic callable from both DDL (immediate reassignment) and startup repair (post-boot recovery), ensuring all owner-bearing rows are properly updated and the StoredOwner catalog table stays in sync.

Pre-1.0 there are no deployed clusters and MIN_WIRE_FORMAT_VERSION
equals WIRE_FORMAT_VERSION, so every wire-version feature gate is
unconditionally true or false inside any cluster that can actually
form — bumping the version only invents a fake rolling-upgrade
requirement. Reset WIRE_FORMAT_VERSION and the rolling-upgrade gate
constants to 1, and drop the now-dead TENANT_ADMIN_ATOMIC_VERSION gate
and its check in favor of always allowing the atomic tenant-creation
path.
@farhan-syah
farhan-syah merged commit 0c6137a into main Jul 20, 2026
@farhan-syah
farhan-syah deleted the fix/drop-user-valid-owner-reassignment branch July 20, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant