Since this is already the fourth follow-up to my original change, I had Opus 5 look for more ways to reach the assertion. It found one more:
D1 DO_POLICY: the "RLS enabled" pseudo-object borrows its table's relname, so it ties with a policy named after that same table. An assert-enabled pg_dump aborts; a production build orders the two by comparing a pg_class OID against a pg_policy OID, which pg_upgrade inverts.
Let's fix that at the same time. Would you like to add that, or would you like me to add it?
Please find the attached v4 version of the patch that also handles RLS policies.