Repository navigation
Fix DROP USER ownership reassignment and wire version reset - #186
Merged
Merged
Conversation
Pre-1.0 there are no deployed clusters and MIN_WIRE_FORMAT_VERSION equals WIRE_FORMAT_VERSION, so every wire-version feature gate is unconditionally true or false inside any cluster that can actually form — bumping the version only invents a fake rolling-upgrade requirement. Reset WIRE_FORMAT_VERSION and the rolling-upgrade gate constants to 1, and drop the now-dead TENANT_ADMIN_ATOMIC_VERSION gate and its check in favor of always allowing the atomic tenant-creation path.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix
DROP USERto properly reassign all object ownership and revoke all grants when a user is dropped. Add database scoping to ownership tracking to correctly handle multi-database environments. Reset wire format version to 1 pre-1.0 since there are no deployed clusters to roll forward.Key Changes
DROP USERnow reassigns ownership of all object types (collections, functions, procedures, triggers, materialized views, sequences, schedules, change streams, continuous aggregates) to the tenant admin, not just collectionsdatabase_idtoStoredOwnerstructure and WAL replay tombstone tracking to correctly isolate ownership by databaseowner_rewrite.rsandownership_fallback.rsfor systematic ownership recovery during catalog integrity repair and DDL fallback pathsWIRE_FORMAT_VERSIONto 1 and remove now-deadTENANT_ADMIN_ATOMIC_VERSIONgate; pre-1.0, all feature gates are unconditionally true or false within any formable clusterDROP USERscenarios across multiple object types and databasesTechnical Details
The core issue: pre-fix,
DROP USERonly reassigned collections it could derive from the user's grant targets. Objects like sequences or functions owned by the user but not directly in grants would be left with dangling owner references, causing catalog integrity checks to fail on the next boot with unrecoverableDanglingReferenceviolations.The fix introduces centralized ownership rewrite logic callable from both DDL (immediate reassignment) and startup repair (post-boot recovery), ensuring all owner-bearing rows are properly updated and the
StoredOwnercatalog table stays in sync.