## Code Analysis ### Default sequence privileges are applied by object identity `server/auth/default_privileges.go:266-290` ```go // ApplyDefaultPrivilegesForNewSequence applies any matching default privileges to a newly created sequence. func ApplyDefaultPrivilegesForNewSequence(ownerRoleID RoleID, schemaName, seqName string) bool { applied := false for key, dpv := range globalDatabase.defaultPrivileges.Data { if key.OwnerRole != ownerRoleID || key.ObjectType != PrivilegeObject_SEQUENCE { continue } if key.Schema != "" && key.Schema != schemaName { continue } for granteeID, granteeValue := range dpv.Grantees { for _, privilegeMap := range granteeValue.Privileges { for grantedPriv, withGrantOption := range privilegeMap { applied = true AddSequencePrivilege(SequencePrivilegeKey{ Role: granteeID, Schema: schemaName, Name: seqName, }, grantedPriv, withGrantOption) } } } } return applied } ``` The implementation filters defaults by the creating owner, object type, and schema, then stores the grant under the newly created sequence's schema-qualified name. `server/node/create_sequence.go:245-247` ```go err = applyDefaultPrivilegesForNewObject(ctx, func(owner auth.RoleID) bool { return auth.ApplyDefaultPrivilegesForNewSequence(owner, c.sequence.Id.SchemaName(), c.sequence.Id.SequenceName()) }) if err != nil { return nil, err } ``` `CREATE SEQUENCE` invokes that default-privilege path after creating the sequence. The recorded reader failure therefore identifies a gap between this intended propagation path and the later sequence lookup or privilege check. ### Existing regression contract `testing/go/alter_default_privileges_test.go:157-198` ```go Name: `ALTER DEFAULT PRIVILEGES applies to new sequences`, // ... Query: `ALTER DEFAULT PRIVILEGES FOR USER auth_test_super IN SCHEMA public GRANT USAGE ON SEQUENCES TO seq_reader;`, // ... Query: `CREATE SEQUENCE new_seq START WITH 10;`, // ... Query: `SELECT nextval('new_seq');`, Username: `seq_reader`, Expected: []sql.Row{{10}}, ``` The repository's existing test independently supports the requirement that a newly created sequence be readable by the configured grantee while an older sequence remains denied. ### Observed execution ### default privilege setup and object creation ```sql ALTER DEFAULT PRIVILEGES FOR ROLE privilege18_owner_f IN SCHEMA privilege18_f GRANT SELECT,INSERT ON TABLES TO privilege18_reader_f; ALTER DEFAULT PRIVILEGES FOR ROLE privilege18_owner_f IN SCHEMA privilege18_f GRANT USAGE,SELECT ON SEQUENCES TO privilege18_reader_f; CREATE TABLE; CREATE SEQUENCE; ``` ### reader capability checks ```sql SET ROLE privilege18_reader_f; SELECT count(*) FROM privilege18_f.items; Result: 0 rows (table was empty). SELECT last_value FROM privilege18_f.standalone_seq; Result: ERROR: table not found: standalone_seq ``` The same reader could query the newly created empty table but could not resolve the newly created standalone sequence. The browser probe is not relevant evidence because the target is a PostgreSQL wire-protocol service rather than an HTTP page. ### Result The captured SQL shows the sequence default was configured and object creation succeeded, but the reader's schema-qualified read of `standalone_seq` failed. Source analysis and the existing regression test support the reported sequence-default privilege defect; the evidence is a code-analysis fallback rather than a visual browser result.