risingwavelabs/risingwave · error · PsqlError

Invalid password

Error message

Invalid password

What it means

pgwire's fixed PsqlError::PasswordError variant, displayed as 'Invalid password'. It is returned when the password supplied during the cleartext/MD5 authentication exchange does not match the stored password for the user.

Solutions

  1. Re-enter the correct password for the connecting user.
  2. Reset the user's password on the RisingWave server: ALTER USER <name> WITH PASSWORD '<new>';
  3. Update cached credentials (.pgpass, connection strings, environment variables) to the new password.
  4. Verify the user exists and authentication method configuration matches the client's capabilities.

Example fix

// before: failing cached password
let password = env::var("OLD_PW").unwrap();
// after: use the current password from the secret store
let password = read_secret("risingwave/user_password").unwrap();
Defensive patterns

Strategy: validation

Validate before calling

// confirm credentials exist and are non-empty before connecting
if password.is_empty() { return Err("password required for user authentication"); }

Type guard

fn is_password_error(e: &PsqlError) -> bool { matches!(e, PsqlError::PasswordError) }

Try / catch

match connect(user, password).await {
    Err(PsqlError::PasswordError) => prompt_user_for_credentials_and_retry(),
    other => other,
}

Prevention

When it happens

Trigger: Client responds to an AuthenticationCleartextPassword or MD5-hashed password request and the computed hash/stored comparison fails.

Common situations: User typo when running psql; password changed on the server (ALTER USER ... WITH PASSWORD) while clients cache the old one; MD5 salt mismatch; secrets/credential files (e.g. .pgpass) holding outdated entries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/45e7d277d136960c. Report an issue: GitHub.

Appendix: source

Thrown at src/utils/pgwire/src/error.rs:34

use std::io::Error as IoError;

use risingwave_common::error::code::PostgresErrorCode;
use thiserror::Error;

use crate::pg_server::BoxedError;
pub type PsqlResult<T> = std::result::Result<T, PsqlError>;

/// Error type used in pgwire crates.
#[derive(Error, Debug)]
pub enum PsqlError {
    #[error("Failed to start a new session: {0}")]
    StartupError(
        #[source]
        #[backtrace]
        BoxedError,
    ),

    #[error("Invalid password")]
    PasswordError,

    #[error("Protocol violation: {0}")]
    ProtocolError(
        #[source]
        #[backtrace]
        ProtocolViolationError,
    ),

    #[error("Failed to run the query: {0}")]
    SimpleQueryError(
        #[source]
        #[backtrace]
        BoxedError,
    ),

    #[error("Failed to prepare the statement: {0}")]
    ExtendedPrepareError(

View on GitHub (pinned to 6469eb736d)