## Code Analysis ### Schema and type mappings enter default-privilege storage `server/ast/alter_default_privileges.go:63-76` ```go func convertDefaultPrivilegeObjectType(objType privilege.ObjectType) (auth.PrivilegeObject, error) { switch objType { case privilege.Schema: return auth.PrivilegeObject_SCHEMA, nil case privilege.Type: return auth.PrivilegeObject_TYPE, nil default: return 0, errors.Errorf("object type %q is not supported in ALTER DEFAULT PRIVILEGES", string(objType)) } } ``` The parser conversion accepts both object types and assigns distinct storage types. `server/node/alter_default_privileges.go:116-137` ```go schemas := n.Schemas if len(schemas) == 0 { schemas = []string{""} } for _, schema := range schemas { key := auth.DefaultPrivilegeKey{ OwnerRole: ownerRole.ID(), Schema: schema, ObjectType: n.ObjectType, } for _, granteeRole := range granteeRoles { for _, priv := range n.Privileges { grantedPrivilege := auth.GrantedPrivilege{ Privilege: priv, GrantedBy: ownerRole.ID(), } if n.Grant { auth.AddDefaultPrivilege(key, granteeRole.ID(), grantedPrivilege, n.GrantOption) } else { auth.RemoveDefaultPrivilege(key, granteeRole.ID(), grantedPrivilege, n.GrantOption) } } } } ``` Execution builds a key containing the owner role, schema scope, and object type, then calls `auth.AddDefaultPrivilege` for each grantee and privilege. ### The catalog read path is hard-coded empty `server/tables/pgcatalog/pg_default_acl.go:44-49,75-78` ```go func (p PgDefaultAclHandler) RowIter(ctx *sql.Context, partition sql.Partition) (sql.RowIter, error) { // pg_default_acl is currently empty, since ALTER DEFAULT PRIVILEGES is not supported. // TODO: fill this in when ALTER DEFAULT PRIVILEGES is supported return emptyRowIter() } func (iter *pgDefaultAclRowIter) Next(ctx *sql.Context) (sql.Row, error) { return nil, io.EOF } ``` The handler does not enumerate the stored default-privilege entries, so a catalog query cannot return rows for the mappings created by the execution path. ### Observed execution ```text $ PGPASSWORD=[REDACTED] psql -U auth_test_super ALTER DEFAULT PRIVILEGES FOR ROLE auth_test_super GRANT USAGE ON SCHEMAS TO readonly_user; ALTER DEFAULT PRIVILEGES ALTER DEFAULT PRIVILEGES FOR ROLE auth_test_super GRANT USAGE ON TYPES TO readonly_user; ALTER DEFAULT PRIVILEGES ``` ```sql SELECT defaclobjtype, defaclnamespace, defaclrole, defaclacl FROM pg_default_acl WHERE defaclrole=(SELECT oid FROM pg_roles WHERE rolname='auth_test_super'); ``` ```text (0 rows) ``` ### Result The captured commands succeeded, but the corresponding `pg_default_acl` readback returned zero rows. The source path supports that the schema and type mappings are accepted and added to default-privilege storage, while the catalog handler always returns an empty iterator, matching the observed missing readback.