risingwavelabs/risingwave · error · PsqlError
Invalid password
Error message
Invalid password
What it means
pgwire's fixed PsqlError::PasswordError variant, displayed as 'Invalid password'. It is returned when the password supplied during the cleartext/MD5 authentication exchange does not match the stored password for the user.
Solutions
- Re-enter the correct password for the connecting user.
- Reset the user's password on the RisingWave server: ALTER USER <name> WITH PASSWORD '<new>';
- Update cached credentials (.pgpass, connection strings, environment variables) to the new password.
- Verify the user exists and authentication method configuration matches the client's capabilities.
Example fix
// before: failing cached password
let password = env::var("OLD_PW").unwrap();
// after: use the current password from the secret store
let password = read_secret("risingwave/user_password").unwrap(); Defensive patterns
Strategy: validation
Validate before calling
// confirm credentials exist and are non-empty before connecting
if password.is_empty() { return Err("password required for user authentication"); } Type guard
fn is_password_error(e: &PsqlError) -> bool { matches!(e, PsqlError::PasswordError) } Try / catch
match connect(user, password).await {
Err(PsqlError::PasswordError) => prompt_user_for_credentials_and_retry(),
other => other,
} Prevention
- Rotate server-side password changes together with all client credential stores.
- Avoid hardcoding passwords; use secret managers or .pgpass kept in sync.
- Test credentials with a lightweight connection before long-running jobs.
When it happens
Trigger: Client responds to an AuthenticationCleartextPassword or MD5-hashed password request and the computed hash/stored comparison fails.
Common situations: User typo when running psql; password changed on the server (ALTER USER ... WITH PASSWORD) while clients cache the old one; MD5 salt mismatch; secrets/credential files (e.g. .pgpass) holding outdated entries.
Related errors
- adlsgen2: cannot configure both shared-key auth…
- adlsgen2: service-principal auth requires all three of…
- ambiguous auth: multiple auth options provided; remove one…
- auth.method=key_pair_object must not set `password`
- BigQuery error
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/45e7d277d136960c.
Report an issue: GitHub.
Appendix: source
Thrown at src/utils/pgwire/src/error.rs:34
use std::io::Error as IoError;
use risingwave_common::error::code::PostgresErrorCode;
use thiserror::Error;
use crate::pg_server::BoxedError;
pub type PsqlResult<T> = std::result::Result<T, PsqlError>;
/// Error type used in pgwire crates.
#[derive(Error, Debug)]
pub enum PsqlError {
#[error("Failed to start a new session: {0}")]
StartupError(
#[source]
#[backtrace]
BoxedError,
),
#[error("Invalid password")]
PasswordError,
#[error("Protocol violation: {0}")]
ProtocolError(
#[source]
#[backtrace]
ProtocolViolationError,
),
#[error("Failed to run the query: {0}")]
SimpleQueryError(
#[source]
#[backtrace]
BoxedError,
),
#[error("Failed to prepare the statement: {0}")]
ExtendedPrepareError(View on GitHub (pinned to 6469eb736d)