## Code Analysis ### Schema and type grants are accepted and stored in auth state `server/ast/alter_default_privileges.go:63-76` ```go func convertDefaultPrivilegeObjectType(objType privilege.ObjectType) (auth.PrivilegeObject, error) { switch objType { case privilege.Schema: return auth.PrivilegeObject_SCHEMA, nil case privilege.Type: return auth.PrivilegeObject_TYPE, nil ``` `server/node/alter_default_privileges.go:125-145` ```go key := auth.DefaultPrivilegeKey{ OwnerRole: ownerRole.ID(), Schema: schema, ObjectType: n.ObjectType, } for _, granteeRole := range granteeRoles { for _, priv := range n.Privileges { grantedPrivilege := auth.GrantedPrivilege{ Privilege: priv, GrantedBy: ownerRole.ID(), } if n.Grant { auth.AddDefaultPrivilege(key, granteeRole.ID(), grantedPrivilege, n.GrantOption) ``` The parser conversion accepts both `SCHEMAS` and `TYPES`. The execution path builds a key containing the owner, schema, and object type, then calls `AddDefaultPrivilege` for each grant. `server/auth/default_privileges.go:53-78` ```go func AddDefaultPrivilege(key DefaultPrivilegeKey, grantee RoleID, privilege GrantedPrivilege, withGrantOption bool) { dpv, ok := globalDatabase.defaultPrivileges.Data[key] if !ok { dpv = DefaultPrivilegeValue{ Key: key, Grantees: builtInDefaultGrantees(key), } } // ... privilegeMap[privilege] = privilegeMap[privilege] || withGrantOption dpv.Grantees[grantee] = granteeValue storeDefaultPrivilegeValue(dpv) } ``` This source path stores the default privilege definition keyed by schema and object type. The catalog read path does not expose that state: `server/tables/pgcatalog/pg_default_acl.go:44-50` ```go func (p PgDefaultAclHandler) RowIter(ctx *sql.Context, partition sql.Partition) (sql.RowIter, error) { // pg_default_acl is currently empty, since ALTER DEFAULT PRIVILEGES is not supported. // This table is also empty in vanilla Postgres until default privileges are altered. // TODO: fill this in when ALTER DEFAULT PRIVILEGES is supported return emptyRowIter() } ``` After grants are accepted and stored, this handler always returns an empty iterator, so `pg_default_acl` cannot read back the configured mappings. ### Observed SQL execution ```sql CREATE ROLE parser8_role_20261009; CREATE SCHEMA parser8_schema_20261009; ALTER DEFAULT PRIVILEGES IN SCHEMA parser8_schema_20261009 GRANT USAGE ON SCHEMAS TO parser8_role_20261009; ALTER DEFAULT PRIVILEGES IN SCHEMA parser8_schema_20261009 GRANT USAGE ON TYPES TO parser8_role_20261009; ``` ```text CREATE ROLE CREATE SCHEMA ALTER DEFAULT PRIVILEGES ALTER DEFAULT PRIVILEGES ``` The namespace-scoped catalog query returned no rows: ```sql SELECT ... FROM pg_default_acl WHERE defaclnamespace = 'parser8_schema_20261009'::regnamespace ...; ``` ```text section | namespace | defaclobjtype | acl ---------+-----------+---------------+----- (0 rows) ``` The full catalog readback was also empty: ```sql SELECT oid, defaclrole, defaclnamespace, defaclobjtype, defaclacl::text FROM pg_default_acl ORDER BY oid DESC LIMIT 20; ``` ```text oid | defaclrole | defaclnamespace | defaclobjtype | defaclacl -----+------------+----------------+---------------+----------- (0 rows) ``` ### Result The runtime commands succeeded, but both the namespace-specific and full `pg_default_acl` readbacks returned zero rows. The source path explains the result: schema/type grants are accepted and stored in auth state, while the catalog handler unconditionally exposes no rows. ### Test context The browser opened an HTTP view of a PostgreSQL wire-protocol target and showed `ERR_EMPTY_RESPONSE`; the SQL commands and readbacks above are the relevant execution evidence.