Native PostgreSQL RLS, owner, view and function fixture
Reported passed · vc9be0e931b79.bb1
View input and acceptance criteria
Input
In a new disposable PostgreSQL 17 database with four synthetic rows and independent non-elevated login roles, inspect RLS default deny, implicit and explicit row checks, conditional update SELECT policies, ordinary owner and FORCE behavior, owner/invoker views and functions, bypass roles, schema/function grants, combined policies, hidden-key errors and TRUNCATE privileges. Run native SQL only; do not connect an AI client, Supabase project or production database.
Acceptance criteria
Six package/source integrity checks and forty-six native SQL observations match. The record is limited to the exact synthetic fixture; it does not evaluate a full skill, Supabase Auth/JWT, Data API/PostgREST, CLI, MCP, Storage, Realtime, vectors, migrations, concurrency or production security.
Recorded outcome
Native PostgreSQL role, RLS policy, view, function, grant, policy composition, hidden-key and TRUNCATE observations on four synthetic rows. No AI client or Supabase Auth/JWT, Data API/PostgREST, CLI, MCP, cloud, Storage, Realtime, vector or migration runtime was executed. This is not a security certification or a full skill evaluation.
{
"format": 1,
"executed_at": "2026-10-04T05:02:19.977667+00:00",
"source_commit": "c9be0e931b7930f7d02126d04774d904c381e7d7",
"package_sha256": "3074c424150934d4dc9a398dcc3e8c570d3805056ab57497d6368dc908310853",
"batch_sha256": "9b33c525a5f575a754aa21caca31c7929e9f74e25a02f6fd721deb45f8606dd4",
"probe_sha256": "8d36c26c1e5243a61b1c4edd52f9f5371fa16b4efd4a9063b96b50d7bb07816f",
"postgresql_version": "17.11",
"server_image_id": "sha256:b0f9560a2de083e2cc7382e75f808c7381a32852a7ec49117deedb300e552b24",
"client_image_id": "sha256:dc1f46972975693fb8f5023f6e5bd37c3a4ea6b2a0472c10997b12a32ddf291f",
"uid": 10001,
"assertions": 52,
"package_integrity_observations": 6,
"postgresql_observations": 46,
"runtime_tested": false,
"cases": [
{
"name": "package_sha256",
"status": "passed",
"detail": null
},
{
"name": "six_preserved_source_and_license_files",
"status": "passed",
"detail": null
},
{
"name": "six_pinned_git_blobs",
"status": "passed",
"detail": null
},
{
"name": "five_declared_changes_reproduce_active_skill",
"status": "passed",
"detail": null
},
{
"name": "active_and_original_reference_closure",
"status": "passed",
"detail": null
},
{
"name": "complete_MIT_notice_and_review_manifest",
"status": "passed",
"detail": null
},
{
"name": "postgresql_17_fixture",
"status": "passed",
"detail": "17.11"
},
{
"name": "alice_has_no_elevated_attributes_or_memberships",
"status": "passed",
"detail": [
false,
false,
false,
false,
false
]
},
{
"name": "bob_has_no_elevated_attributes_or_memberships",
"status": "passed",
"detail": [
false,
false,
false,
false,
false
]
},
{
"name": "owner_has_no_elevated_attributes_or_memberships",
"status": "passed",
"detail": [
false,
false,
false,
false,
false
]
},
{
"name": "alice_schema_usage_without_create",
"status": "passed",
"detail": null
},
{
"name": "alice_no_temporary_table_privilege",
"status": "passed",
"detail": null
},
{
"name": "grants_without_RLS_expose_all_four_rows",
"status": "passed",
"detail": null
},
{
"name": "RLS_without_applicable_policy_denies_all_rows",
"status": "passed",
"detail": null
},
{
"name": "ordinary_table_owner_bypasses_before_FORCE",
"status": "passed",
"detail": null
},
{
"name": "ALL_policy_omits_explicit_check",
"status": "passed",
"detail": null
},
{
"name": "alice_only_own_two_rows",
"status": "passed",
"detail": null
},
{
"name": "bob_only_own_two_rows",
"status": "passed",
"detail": null
},
{
"name": "own_conditional_update_allowed_and_rolled_back",
"status": "passed",
"detail": [
[
101
]
]
},
{
"name": "other_tenant_update_selects_no_rows",
"status": "passed",
"detail": []
},
{
"name": "other_tenant_delete_selects_no_rows",
"status": "passed",
"detail": []
},
{
"name": "implicit_WITH_CHECK_blocks_owner_reassignment",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "implicit_WITH_CHECK_blocks_other_tenant_insert",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "own_insert_allowed_and_rolled_back",
"status": "passed",
"detail": [
[
103
]
]
},
{
"name": "own_delete_allowed_and_rolled_back",
"status": "passed",
"detail": [
[
102
]
]
},
{
"name": "explicit_WITH_CHECK_also_blocks_owner_reassignment",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "conditional_UPDATE_RETURNING_without_SELECT_policy_returns_zero",
"status": "passed",
"detail": []
},
{
"name": "matching_SELECT_policy_allows_conditional_UPDATE_RETURNING",
"status": "passed",
"detail": [
[
101
]
]
},
{
"name": "default_owner_view_exposes_four_before_FORCE",
"status": "passed",
"detail": null
},
{
"name": "security_invoker_view_sees_caller_two_rows",
"status": "passed",
"detail": null
},
{
"name": "new_definer_function_has_PUBLIC_execute_default",
"status": "passed",
"detail": null
},
{
"name": "owner_definer_function_sees_four_before_FORCE",
"status": "passed",
"detail": null
},
{
"name": "invoker_function_sees_caller_two_rows",
"status": "passed",
"detail": null
},
{
"name": "FORCE_subjects_ordinary_owner_to_default_deny",
"status": "passed",
"detail": null
},
{
"name": "owner_definer_function_obeys_FORCE_and_sees_zero",
"status": "passed",
"detail": null
},
{
"name": "default_owner_view_obeys_FORCE_and_sees_zero",
"status": "passed",
"detail": null
},
{
"name": "security_invoker_view_still_sees_two_after_FORCE",
"status": "passed",
"detail": null
},
{
"name": "BYPASSRLS_role_still_sees_four_after_FORCE",
"status": "passed",
"detail": null
},
{
"name": "superuser_still_sees_four_after_FORCE",
"status": "passed",
"detail": null
},
{
"name": "superuser_owned_definer_still_sees_four_after_FORCE",
"status": "passed",
"detail": null
},
{
"name": "alice_cannot_SET_ROLE_to_BYPASSRLS_role",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "row_security_off_errors_instead_of_bypassing",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "revoked_function_EXECUTE_blocks_call",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "schema_USAGE_required_even_with_function_EXECUTE",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "permissive_OR_policy_widens_to_four_rows",
"status": "passed",
"detail": null
},
{
"name": "restrictive_AND_policy_narrows_back_to_two_rows",
"status": "passed",
"detail": null
},
{
"name": "hidden_other_tenant_primary_key_conflict_is_observable",
"status": "passed",
"detail": {
"sqlstate": "23505"
}
},
{
"name": "alice_has_no_TRUNCATE_grant",
"status": "passed",
"detail": null
},
{
"name": "TRUNCATE_denied_by_privilege",
"status": "passed",
"detail": {
"sqlstate": "42501"
}
},
{
"name": "explicit_TRUNCATE_grant_is_not_limited_by_RLS",
"status": "passed",
"detail": null
},
{
"name": "all_original_synthetic_rows_restored",
"status": "passed",
"detail": null
},
{
"name": "auxiliary_update_payload_restored",
"status": "passed",
"detail": null
}
],
"rejected_operations": [
{
"operation": "implicit_WITH_CHECK_blocks_owner_reassignment",
"sqlstate": "42501"
},
{
"operation": "implicit_WITH_CHECK_blocks_other_tenant_insert",
"sqlstate": "42501"
},
{
"operation": "explicit_WITH_CHECK_also_blocks_owner_reassignment",
"sqlstate": "42501"
},
{
"operation": "alice_cannot_SET_ROLE_to_BYPASSRLS_role",
"sqlstate": "42501"
},
{
"operation": "row_security_off_errors_instead_of_bypassing",
"sqlstate": "42501"
},
{
"operation": "revoked_function_EXECUTE_blocks_call",
"sqlstate": "42501"
},
{
"operation": "schema_USAGE_required_even_with_function_EXECUTE",
"sqlstate": "42501"
},
{
"operation": "hidden_other_tenant_primary_key_conflict_is_observable",
"sqlstate": "23505"
},
{
"operation": "TRUNCATE_denied_by_privilege",
"sqlstate": "42501"
}
],
"scope": "Native PostgreSQL role, RLS policy, view, function, grant, policy composition, hidden-key and TRUNCATE observations on four synthetic rows. No AI client or Supabase Auth/JWT, Data API/PostgREST, CLI, MCP, cloud, Storage, Realtime, vector or migration runtime was executed. This is not a security certification or a full skill evaluation.",
"isolation": "Independent temporary PostgreSQL database and internal Docker network; synthetic data only. No production data, production environment or production storage is mounted. Non-root read-only runner, dropped capabilities, no-new-privileges, resource limits. Dangerous grant demonstrations are rolled back or removed in the disposable fixture."
}Environment
Independent temporary PostgreSQL database and internal Docker network; synthetic data only. No production data, production environment or production storage is mounted. Non-root read-only runner, dropped capabilities, no-new-privileges, resource limits. Dangerous grant demonstrations are rolled back or removed in the disposable fixture. PostgreSQL 17.11; server sha256:b0f9560a2de083e2cc7382e75f808c7381a32852a7ec49117deedb300e552b24; client sha256:dc1f46972975693fb8f5023f6e5bd37c3a4ea6b2a0472c10997b12a32ddf291f.
Package SHA-256: 3074c424150934d4dc9a398dcc3e8c570d3805056ab57497d6368dc908310853
Outcome recorded: 2026-10-04 05:02 UTC