• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

supabase / supautils / 35088465794
95%

Build:
DEFAULT BRANCH: master
Ran 16 Sep 2026 11:06AM UTC
Jobs 1
Files 12
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

16 Sep 2026 11:05AM UTC coverage: 94.149% (+0.1%) from 94.008%
35088465794

push

github

web-flow
fix: don't take ACCESS EXCLUSIVE locks on allowlisted tables during policy checks (#228)

* fix: don't take ACCESS EXCLUSIVE locks on allowlisted tables during policy checks

The policy and drop-trigger grant checks resolved every table in the role's
allowlist with an ACCESS EXCLUSIVE lock just to get its OID for comparison. The
locks were held until the transaction ended, so creating a policy inside a long
transaction kept unrelated auth/storage tables locked and blocked everything
behind them.

Resolve the allowlist entries with NoLock instead - the target is already held
under ACCESS EXCLUSIVE and only the OID is used. Also moved the shared scan into
is_table_in_grant_list() so both checks go through one path.

* fix: match the target-table lock to the policy statement in the grant check

The grant check always resolved the target table with ACCESS EXCLUSIVE, but
COMMENT ON POLICY only takes ACCESS SHARE on the table, so the check was
over-locking it. Pass the lock mode in from each call site: ACCESS EXCLUSIVE for
create/alter/drop policy, ACCESS SHARE for comment on policy.

* fix: correct the lock comment in the grant-list helper

The caller doesn't always hold ACCESS EXCLUSIVE - COMMENT ON POLICY passes
ACCESS SHARE - so just say the caller has already locked the target.

17 of 18 new or added lines in 4 files covered. (94.44%)

1400 of 1487 relevant lines covered (94.15%)

257.5 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
97.56
-1.03% src/utils.c
Jobs
ID Job ID Ran Files Coverage
1 35088465794.1 16 Sep 2026 11:06AM UTC 12
94.15
GitHub Action Run
Source Files on build 35088465794
  • Tree
  • List 12
  • Changed 4
  • Source Changed 4
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35088465794
  • 42cc7f0c on github
  • Prev Build on master (#34461366589)
  • Next Build on master (#35205738952)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc