Finding
Draft #235 introduced workforce_validation_role as NOLOGIN and originally set ALTER ROLE workforce_validation_role SET search_path = workforce_validation, pg_catalog; its README/PostgreSQL acceptance treated the resulting rolconfig as runtime isolation evidence.
PostgreSQL 18 documents that role-specific configuration defaults are applied only when the role starts a new session. SET ROLE and SET SESSION AUTHORIZATION do not process those role-specific settings. A NOLOGIN role therefore cannot make its ALTER ROLE ... SET search_path entry a runtime isolation boundary for a login that later changes role.
Test-first repair on canonical #235
f63c6e164c5a2534538e83b87968d4d94228ebfa: migration contract requires no owner ALTER ROLE ... SET search_path default.
7dad37bf9f5ded39b2224597d0fa9c2617f52361: PostgreSQL behavior contract sets session search_path=public, executes SET ROLE workforce_validation_role, and proves the path remains public.
fd87b719bd581a64ca84ca679530e264ed6f167f: removes the ineffective setting while preserving deny-default role flags, schema ownership, and PUBLIC revocation.
a04c8b4cd58145f9e74a085d3fdb037d90966012: documentation requires a distinct least-privilege runtime role, schema-qualified workforce_validation relations, and explicit function-level search_path for any SECURITY DEFINER code.
The canonical #235 branch subsequently advanced through #239/#240 to exact ccb5c0c58dc74c1d7eee59431e6337c207fcac35. Those application-boundary repairs do not alter the #238 migration, role flags, PostgreSQL behavior contract, Foundation workflow, or runtime-role requirement.
Exact-head acceptance
Current Foundation 33954469089 / Repository quality 101275139627 is queued before checkout; Security 33954468968, SAST 33954468946, and CodeQL PR 33954468879 are non-terminal. No current-head hosted GREEN or PostgreSQL GREEN is claimed. Prior exact a04c8b4... static review remains direct review evidence for this migration/runtime-semantics change, but it does not substitute for current hosted or formal approval evidence.
Keep this issue open until #235 has terminal current-head Foundation/PostgreSQL/security/review evidence and normal protected integration or a verified successor fully carries this test and repair. Do not close on source completion alone.
Finding
Draft #235 introduced
workforce_validation_roleasNOLOGINand originally setALTER ROLE workforce_validation_role SET search_path = workforce_validation, pg_catalog; its README/PostgreSQL acceptance treated the resultingrolconfigas runtime isolation evidence.PostgreSQL 18 documents that role-specific configuration defaults are applied only when the role starts a new session.
SET ROLEandSET SESSION AUTHORIZATIONdo not process those role-specific settings. A NOLOGIN role therefore cannot make itsALTER ROLE ... SET search_pathentry a runtime isolation boundary for a login that later changes role.Test-first repair on canonical #235
f63c6e164c5a2534538e83b87968d4d94228ebfa: migration contract requires no ownerALTER ROLE ... SET search_pathdefault.7dad37bf9f5ded39b2224597d0fa9c2617f52361: PostgreSQL behavior contract sets sessionsearch_path=public, executesSET ROLE workforce_validation_role, and proves the path remainspublic.fd87b719bd581a64ca84ca679530e264ed6f167f: removes the ineffective setting while preserving deny-default role flags, schema ownership, and PUBLIC revocation.a04c8b4cd58145f9e74a085d3fdb037d90966012: documentation requires a distinct least-privilege runtime role, schema-qualifiedworkforce_validationrelations, and explicit function-levelsearch_pathfor anySECURITY DEFINERcode.The canonical #235 branch subsequently advanced through #239/#240 to exact
ccb5c0c58dc74c1d7eee59431e6337c207fcac35. Those application-boundary repairs do not alter the #238 migration, role flags, PostgreSQL behavior contract, Foundation workflow, or runtime-role requirement.Exact-head acceptance
Current Foundation
33954469089/ Repository quality101275139627is queued before checkout; Security33954468968, SAST33954468946, and CodeQL PR33954468879are non-terminal. No current-head hosted GREEN or PostgreSQL GREEN is claimed. Prior exacta04c8b4...static review remains direct review evidence for this migration/runtime-semantics change, but it does not substitute for current hosted or formal approval evidence.Keep this issue open until #235 has terminal current-head Foundation/PostgreSQL/security/review evidence and normal protected integration or a verified successor fully carries this test and repair. Do not close on source completion alone.