## Code Analysis ### New-routine detection retains the signature, but default application does not `server/node/create_function.go:143-179` ```go funcID := id.NewFunction(schemaName, c.FunctionName, inputParamTypes...) // A replaced routine keeps its existing privileges, so default privileges only apply to new routines replaced := c.Replace && funcCollection.HasFunction(ctx, funcID) ... if !replaced { err = applyDefaultPrivilegesForNewObject(ctx, func(owner auth.RoleID) bool { return auth.ApplyDefaultPrivilegesForNewRoutine(owner, schemaName, c.FunctionName) }) } ``` The function identity used to detect a new or replaced routine includes `inputParamTypes`, but the default-privilege call receives only the schema and routine name. This means the signature information is not carried into the default-privilege application path. `server/auth/default_privileges.go:293-327` ```go func ApplyDefaultPrivilegesForNewRoutine(ownerRoleID RoleID, schemaName, routineName string) bool { ... AddRoutinePrivilege(RoutinePrivilegeKey{ Role: granteeID, Schema: schemaName, Name: routineName, }, grantedPriv, withGrantOption) ... } ``` Both default-grant construction paths populate the role, schema, and routine name but leave `ArgTypes` unset. The privilege key defines `ArgTypes` as the comma-separated argument types that identify a routine signature (`server/auth/routine_privileges.go:26-33`), so these generated keys cannot distinguish `calculate(integer)` from `calculate(text)`. ### Observed execution The captured run created both overloads and then read the routine catalog and default-privilege catalog: ```text CREATE ROLE CREATE ROLE CREATE SCHEMA GRANT ALTER DEFAULT PRIVILEGES SET CREATE FUNCTION CREATE FUNCTION RESET ``` ```text proname | identity_args | proacl -----------+---------------+-------- calculate | | calculate | | (2 rows) defaclrole | defaclnamespace | defaclobjtype | defaclacl ------------+-----------------+---------------+----------- (0 rows) ``` The run therefore confirms creation of two `calculate` rows but does not provide a reliable per-signature ACL readback. The source path is the support for the reported defect: it recognizes signatures when deciding whether a routine is new, then records default privileges without the argument types required to keep overloads separate. ### Result Source analysis supports the reported failure that default EXECUTE permissions cannot be represented independently for a newly created routine overload. The runtime readback is incomplete and is included only as context; it does not by itself prove the exact ACL outcome. ### Test context No stubs, mocks, or bypasses were recorded for this test. The captured catalog readback was incomplete, so the conclusion relies on the quoted production source rather than treating the empty ACL columns as proof of the exact per-signature result.