## Code Analysis ### The requested revoke form is parsed into grant-option state `postgres/parser/parser/sql.y:1909-1916` ```yacc adp_abbreviated_grant_or_revoke: GRANT privileges ON targets_for_alter_def_priv TO opt_role_list opt_with_grant_option | REVOKE opt_grant_option_for privileges ON targets_for_alter_def_priv FROM opt_role_list opt_drop_behavior { $$.val = &tree.AlterDefaultPrivileges{GrantOption: $2.bool(), Privileges: $3.privilegeList(), Target: $5.targetList(), Grantees: $7.strs(), DropBehavior: $8.dropBehavior()} } ``` The grammar accepts `REVOKE GRANT OPTION FOR ... RESTRICT` and preserves both the grant-option flag and drop behavior in the `AlterDefaultPrivileges` node. ### The default-privilege executor has a grant-option-only mutation path `server/node/alter_default_privileges.go:129-138` ```go for _, priv := range n.Privileges { grantedPrivilege := auth.GrantedPrivilege{ Privilege: priv, GrantedBy: ownerRole.ID(), } if n.Grant { auth.AddDefaultPrivilege(key, granteeRole.ID(), grantedPrivilege, n.GrantOption) } else { auth.RemoveDefaultPrivilege(key, granteeRole.ID(), grantedPrivilege, n.GrantOption) } } ``` After parsing, a revoke with `GrantOption` set is routed to `RemoveDefaultPrivilege` rather than being inherently unsupported by the default-privilege model. ### The mutation function is designed to retain the privilege and clear delegation `server/auth/default_privileges.go:79-103` ```go // RemoveDefaultPrivilege removes a default privilege entry from the global database. // If grantOptionOnly is true, only the WITH GRANT OPTION flag is revoked. func RemoveDefaultPrivilege(key DefaultPrivilegeKey, grantee RoleID, privilege GrantedPrivilege, grantOptionOnly bool) { dpv, ok := globalDatabase.defaultPrivileges.Data[key] if !ok { return } granteeValue, ok := dpv.Grantees[grantee] if !ok { return } privilegeMap, ok := granteeValue.Privileges[privilege.Privilege] if !ok { return } if grantOptionOnly { if privilege.GrantedBy.IsValid() { if _, ok = privilegeMap[privilege]; ok { privilegeMap[privilege] = false } } else { for k := range privilegeMap { privilegeMap[k] = false } } } } ``` This source path explicitly models removing only `WITH GRANT OPTION`, which is the behavior required by the test while retaining the underlying privilege entry. ### Converter rejects the otherwise parsed revoke form `server/ast/revoke.go:144-158` ```go default: return nil, errors.Errorf("this form of REVOKE is not yet supported") } return vitess.InjectedStatement{ Statement: &pgnodes.Revoke{ RevokeTable: revokeTable, RevokeSchema: revokeSchema, RevokeDatabase: revokeDatabase, RevokeSequence: revokeSequence, RevokeRoutine: revokeRoutine, RevokeRole: nil, FromRoles: node.Grantees, GrantedBy: node.GrantedBy, GrantOptionFor: node.GrantOptionFor, Cascade: node.DropBehavior == tree.DropCascade, }, Children: nil, }, nil ``` The converter can return the unsupported-form error before producing the revoke statement. That prevents the parsed operation from reaching the default-privilege mutation path. ### Observed execution The runner executed the grant and revoke through `psql` as `auth_test_super`: ```sh PGPASSWORD=[REDACTED] psql -h localhost -p 5432 -U auth_test_super -d postgres -v ON_ERROR_STOP=1 <<'SQL' ALTER DEFAULT PRIVILEGES FOR USER auth_test_super IN SCHEMA public GRANT SELECT ON TABLES TO readonly_user WITH GRANT OPTION; REVOKE GRANT OPTION FOR SELECT ON TABLES FROM readonly_user RESTRICT; CREATE TABLE parser6_probe_table (id int); INSERT INTO parser6_probe_table VALUES (6); SQL ``` The captured command output was: ```text DROP TABLE DROP ROLE CREATE ROLE ALTER DEFAULT PRIVILEGES ERROR: this form of REVOKE is not yet supported SELECT_AS_READONLY ERROR: table not found: parser6_probe_table DELEGATION_ATTEMPT ERROR: role "readonly_user" does not have permission to grant this privilege ``` ### Result The grant setup succeeded, but `REVOKE GRANT OPTION FOR ... RESTRICT` was rejected before the follow-up table/read and delegation assertions could establish the required round-trip semantics. The runtime error and source path support the reported unsupported revoke operation. ### Test context The SQL test ran against the local SQL-focused service using direct `psql`; the browser page only displayed the captured result for evidence timestamping.