use the same inconsistent priv_user@host pair for SET ROLE privilege checks, just as check_access() does