fix(engine): finalize pending partition detach for restricted users
Closes #795.
Creating a restricted clone failed with cannot alter partition "…" with an incomplete detach when the snapshot held a partition whose DETACH PARTITION ... CONCURRENTLY had not finished (pg_inherits.inhdetachpending, PG14+). Postgres rejects any ALTER on such a partition, so the ALTER ... OWNER TO loop in restrictionTemplate aborted and every restricted clone of that snapshot failed.
The flag is committed before the detach starts waiting for concurrent transactions, so a snapshot taken during a routine concurrent detach lands in this state too, not only one taken after an interrupted detach.
Changes:
restrictionTemplate(engine/internal/provision/databases/postgres/postgres_mgmt.go) runsALTER TABLE <parent> DETACH PARTITION <partition> FINALIZEon every pending partition before the relation ownership loop. The lookup sits behind aserver_version_num >= 140000check, sinceinhdetachpendingdoes not exist earlier, and covers only the schemas and relation kinds the ownership loop alters.TestCreateUser_RestrictedOwnsPartitions_IntegrationrunsCreateUseragainst PG13, PG14 and PG17. On 14 and 17 it leaves a partition with an incomplete detach by cancelling the concurrent detach while another transaction still holds the parent.
Skipping the partition, the first option in the issue, is not enough on its own: the table keeps its owner, and ALTER SEQUENCE ... OWNER TO then fails for any sequence linked to it (cannot change owner of sequence). The test partition owns a serial sequence to cover that.
A restricted clone no longer shows the detach as pending; the partition becomes a standalone table. Queries through the parent return the same rows, since a partition with a pending detach is already excluded from them.