{"Entry":{"collection":"sql","key":"security-label","name":"SECURITY LABEL","aliases":["security-label"],"metadata":{"aliases":["security-label"],"changed_in":["9.2","9.3","9.4","10","11","12"],"changes":[{"from":"9.0","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":[],"removed":[]},"status":"added","synopsis":null,"to":"9.1"},{"from":"9.1","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":[],"removed":[]},"status":"changed","synopsis":{"added":["AGGREGATE agg_name (agg_type [, ...] ) |","DATABASE object_name |","ROLE object_name |","SEQUENCE object_name |","TABLESPACE object_name |"],"removed":[]},"to":"9.2"},{"from":"9.2","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":[],"removed":[]},"status":"changed","synopsis":{"added":["EVENT TRIGGER object_name |","MATERIALIZED VIEW object_name |"],"removed":[]},"to":"9.3"},{"from":"9.3","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["description","parameters"],"removed":[]},"status":"changed","synopsis":{"added":["AGGREGATE aggregate_name ( aggregate_signature ) |","* |","[ argmode ] [ argname ] argtype [ , ... ] |","[ [ argmode ] [ argname ] argtype [ , ... ] ] ORDER BY [ argmode ] [ argname ] argtype [ , ... ]"],"removed":["AGGREGATE agg_name (agg_type [, ...] ) |"]},"to":"9.4"},{"from":"9.4","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["see_also"],"removed":[]},"status":"changed","synopsis":null,"to":"9.5"},{"from":"9.6","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["description"],"removed":[]},"status":"changed","synopsis":{"added":["FUNCTION function_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |","PUBLICATION object_name |","SEQUENCE object_name |","SUBSCRIPTION object_name |"],"removed":[]},"to":"10"},{"from":"10","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["parameters","examples"],"removed":[]},"status":"changed","synopsis":{"added":["PROCEDURE procedure_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |","ROLE object_name |","ROUTINE routine_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |","} IS { string_literal | NULL }"],"removed":["} IS 'label'"]},"to":"11"},{"from":"11","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":[],"removed":[]},"status":"changed","synopsis":{"added":["FOREIGN TABLE object_name |"],"removed":[]},"to":"12"},{"from":"12","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["description"],"removed":[]},"status":"changed","synopsis":null,"to":"13"},{"from":"13","purpose_changed":false,"renamed":null,"sections":{"added":[],"changed":["parameters"],"removed":[]},"status":"changed","synopsis":null,"to":"14"}],"content_hash":"6d09339c64c03aba9a520450a3b2ec24e1c1f6c25fab30c122a9ba396a1c09b7","editorial":{},"first_version":"9.1","group":"role","imported_at":"2026-09-27T17:57:26.589463+08:00","last_version":"20","name":"SECURITY LABEL","object":"LABEL","position":5006,"present_in":["9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"purpose":"define or change a security label applied to an object","purpose_zh":"","related":[],"slug":"security-label","source_rev":"b7bd9cda","synopsis":"SECURITY LABEL [ FOR provider ] ON\n{\nTABLE object_name |\nCOLUMN table_name.column_name |\nAGGREGATE aggregate_name ( aggregate_signature ) |\nDATABASE object_name |\nDOMAIN object_name |\nEVENT TRIGGER object_name |\nFOREIGN TABLE object_name |\nFUNCTION function_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nLARGE OBJECT large_object_oid |\nMATERIALIZED VIEW object_name |\n[ PROCEDURAL ] LANGUAGE object_name |\nPROCEDURE procedure_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nPUBLICATION object_name |\nROLE object_name |\nROUTINE routine_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nSCHEMA object_name |\nSEQUENCE object_name |\nSUBSCRIPTION object_name |\nTABLESPACE object_name |\nTYPE object_name |\nVIEW object_name\n} IS { string_literal | NULL }\n\nwhere aggregate_signature is:\n\n* |\n[ argmode ] [ argname ] argtype [ , ... ] |\n[ [ argmode ] [ argname ] argtype [ , ... ] ] ORDER BY [ argmode ] [ argname ] argtype [ , ... ]","verb":"SECURITY"}},"Definition":{"Collection":"sql","Key":"security-label","SourceDatabase":"center","Version":"18","SourceTable":"sqlcmd","SourceKey":"security-label","SourceRevision":"b7bd9cda","Facts":{"anchor":"SQL-SECURITY-LABEL","file":"sql-security-label.html","lang":"en","name":"SECURITY LABEL","purpose":"define or change a security label applied to an object","purpose_zh":"","related":[],"sections":[{"html":"\u003cp\u003e\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e applies a security label to a database object. An arbitrary number of security labels, one per label provider, can be associated with a given database object. Label providers are loadable modules which register themselves by using the function \u003ccode class=\"function\"\u003eregister_label_provider\u003c/code\u003e.\u003c/p\u003e\u003cdiv class=\"note\"\u003e\u003ch3\u003eNote\u003c/h3\u003e\u003cp\u003e\u003ccode class=\"function\"\u003eregister_label_provider\u003c/code\u003e is not an SQL function; it can only be called from C code loaded into the backend.\u003c/p\u003e\u003c/div\u003e\u003cp\u003eThe label provider determines whether a given label is valid and whether it is permissible to assign that label to a given object. The meaning of a given label is likewise at the discretion of the label provider. \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e places no restrictions on whether or how a label provider must interpret security labels; it merely provides a mechanism for storing them. In practice, this facility is intended to allow integration with label-based mandatory access control (MAC) systems such as \u003cspan class=\"productname\"\u003eSELinux\u003c/span\u003e. Such systems make all access control decisions based on object labels, rather than traditional discretionary access control (DAC) concepts such as users and groups.\u003c/p\u003e\u003cp\u003eYou must own the database object to use \u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e.\u003c/p\u003e","key":"description","title":"Description"},{"html":"\u003cdiv class=\"variablelist\"\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003etable_name.column_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003efunction_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eprocedure_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eroutine_name\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe name of the object to be labeled. Names of objects that reside in schemas (tables, functions, etc.) can be schema-qualified.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eprovider\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe name of the provider with which this label is to be associated. The named provider must be loaded and must consent to the proposed labeling operation. If exactly one provider is loaded, the provider name may be omitted for brevity.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe mode of a function, procedure, or aggregate argument: \u003ccode class=\"literal\"\u003eIN\u003c/code\u003e, \u003ccode class=\"literal\"\u003eOUT\u003c/code\u003e, \u003ccode class=\"literal\"\u003eINOUT\u003c/code\u003e, or \u003ccode class=\"literal\"\u003eVARIADIC\u003c/code\u003e. If omitted, the default is \u003ccode class=\"literal\"\u003eIN\u003c/code\u003e. Note that \u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e does not actually pay any attention to \u003ccode class=\"literal\"\u003eOUT\u003c/code\u003e arguments, since only the input arguments are needed to determine the function's identity. So it is sufficient to list the \u003ccode class=\"literal\"\u003eIN\u003c/code\u003e, \u003ccode class=\"literal\"\u003eINOUT\u003c/code\u003e, and \u003ccode class=\"literal\"\u003eVARIADIC\u003c/code\u003e arguments.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe name of a function, procedure, or aggregate argument. Note that \u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e does not actually pay any attention to argument names, since only the argument data types are needed to determine the function's identity.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe data type of a function, procedure, or aggregate argument.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003elarge_object_oid\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe OID of the large object.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003ePROCEDURAL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThis is a noise word.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003estring_literal\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eThe new setting of the security label, written as a string literal.\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eNULL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003eWrite \u003ccode class=\"literal\"\u003eNULL\u003c/code\u003e to drop the security label.\u003c/p\u003e\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","key":"parameters","title":"Parameters"},{"html":"\u003cp\u003eThe following example shows how the security label of a table could be set or changed:\u003c/p\u003e\u003cpre class=\"programlisting\"\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS 'system_u:object_r:sepgsql_table_t:s0';\n\u003c/pre\u003e\u003cp\u003eTo remove the label:\u003c/p\u003e\u003cpre class=\"programlisting\"\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS NULL;\n\u003c/pre\u003e","key":"examples","title":"Examples"},{"html":"\u003cp\u003eThere is no \u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e command in the SQL standard.\u003c/p\u003e","key":"compatibility","title":"Compatibility"},{"html":"\u003cspan class=\"simplelist\"\u003e\u003ca href=\"/docs/18/sepgsql.html\" title=\"F.40. sepgsql — SELinux-, label-based mandatory access control (MAC) security module\"\u003esepgsql\u003c/a\u003e, \u003ccode class=\"filename\"\u003esrc/test/modules/dummy_seclabel\u003c/code\u003e\u003c/span\u003e","key":"see_also","title":"See Also"}],"sections_same_as":"","slug":"18","synopsis_html":"SECURITY LABEL [ FOR \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprovider\u003c/code\u003e\u003c/em\u003e ] ON\n{\n  TABLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  COLUMN \u003cem class=\"replaceable\"\u003e\u003ccode\u003etable_name\u003c/code\u003e\u003c/em\u003e.\u003cem class=\"replaceable\"\u003e\u003ccode\u003ecolumn_name\u003c/code\u003e\u003c/em\u003e |\n  AGGREGATE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_name\u003c/code\u003e\u003c/em\u003e ( \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_signature\u003c/code\u003e\u003c/em\u003e ) |\n  DATABASE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  DOMAIN \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  EVENT TRIGGER \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  FOREIGN TABLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  FUNCTION \u003cem class=\"replaceable\"\u003e\u003ccode\u003efunction_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  LARGE OBJECT \u003cem class=\"replaceable\"\u003e\u003ccode\u003elarge_object_oid\u003c/code\u003e\u003c/em\u003e |\n  MATERIALIZED VIEW \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  [ PROCEDURAL ] LANGUAGE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  PROCEDURE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprocedure_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  PUBLICATION \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  ROLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  ROUTINE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eroutine_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  SCHEMA \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  SEQUENCE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  SUBSCRIPTION \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  TABLESPACE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  TYPE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  VIEW \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e\n} IS { \u003cem class=\"replaceable\"\u003e\u003ccode\u003estring_literal\u003c/code\u003e\u003c/em\u003e | NULL }\n\n\u003cspan class=\"phrase\"\u003ewhere \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_signature\u003c/code\u003e\u003c/em\u003e is:\u003c/span\u003e\n\n* |\n[ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ] |\n[ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ] ] ORDER BY [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ]","synopsis_text":"SECURITY LABEL [ FOR provider ] ON\n{\nTABLE object_name |\nCOLUMN table_name.column_name |\nAGGREGATE aggregate_name ( aggregate_signature ) |\nDATABASE object_name |\nDOMAIN object_name |\nEVENT TRIGGER object_name |\nFOREIGN TABLE object_name |\nFUNCTION function_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nLARGE OBJECT large_object_oid |\nMATERIALIZED VIEW object_name |\n[ PROCEDURAL ] LANGUAGE object_name |\nPROCEDURE procedure_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nPUBLICATION object_name |\nROLE object_name |\nROUTINE routine_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nSCHEMA object_name |\nSEQUENCE object_name |\nSUBSCRIPTION object_name |\nTABLESPACE object_name |\nTYPE object_name |\nVIEW object_name\n} IS { string_literal | NULL }\n\nwhere aggregate_signature is:\n\n* |\n[ argmode ] [ argname ] argtype [ , ... ] |\n[ [ argmode ] [ argname ] argtype [ , ... ] ] ORDER BY [ argmode ] [ argname ] argtype [ , ... ]"},"ManualEvidence":{},"MeasuredEvidence":{}},"Text":{"Collection":"sql","Key":"security-label","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"SECURITY LABEL","Summary":"定义或更改应用于对象的安全标签","BodyHTML":"\u003cpre\u003eSECURITY LABEL [ FOR provider ] ON\n{\nTABLE object_name |\nCOLUMN table_name.column_name |\nAGGREGATE aggregate_name ( aggregate_signature ) |\nDATABASE object_name |\nDOMAIN object_name |\nEVENT TRIGGER object_name |\nFOREIGN TABLE object_name |\nFUNCTION function_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nLARGE OBJECT large_object_oid |\nMATERIALIZED VIEW object_name |\n[ PROCEDURAL ] LANGUAGE object_name |\nPROCEDURE procedure_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nPUBLICATION object_name |\nROLE object_name |\nROUTINE routine_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nSCHEMA object_name |\nSEQUENCE object_name |\nSUBSCRIPTION object_name |\nTABLESPACE object_name |\nTYPE object_name |\nVIEW object_name\n} IS { string_literal | NULL }\n\n其中 aggregate_signature 是：\n\n* |\n[ argmode ] [ argname ] argtype [ , ... ] |\n[ [ argmode ] [ argname ] argtype [ , ... ] ] ORDER BY [ argmode ] [ argname ] argtype [ , ... ]\u003c/pre\u003e\u003csection\u003e\u003ch2\u003e描述\u003c/h2\u003e\u003cp\u003e\u003ccode\u003eSECURITY LABEL\u003c/code\u003e为数据库对象设置安全标签。一个给定的数据库对象可以关联任意数量的安全标签，每个标签提供者对应一个。标签提供者是使用函数\u003ccode\u003eregister_label_provider\u003c/code\u003e注册自身的可加载模块。\u003c/p\u003e\u003cdiv\u003e\u003ch3\u003e注意\u003c/h3\u003e\u003cp\u003e\u003ccode\u003eregister_label_provider\u003c/code\u003e不是一个 SQL 函数；它只能从加载到后端的 C 代码中调用。\u003c/p\u003e\u003c/div\u003e\u003cp\u003e标签提供者决定给定标签是否有效，以及是否允许将该标签赋给给定对象。给定标签的含义同样由标签提供者自行决定。\u003cspan\u003ePostgreSQL\u003c/span\u003e不限制标签提供者是否解释安全标签，也不限制其如何解释；它仅提供一种存储安全标签的机制。实际上，此功能旨在支持与基于标签的强制访问控制（MAC）系统（例如\u003cspan\u003eSELinux\u003c/span\u003e）集成。这类系统基于对象标签，而不是基于用户和组等传统的自主访问控制（DAC）概念，做出所有访问控制决策。\u003c/p\u003e\u003cp\u003e要使用\u003ccode\u003eSECURITY LABEL\u003c/code\u003e，你必须拥有该数据库对象。\u003c/p\u003e\u003c/section\u003e\u003csection\u003e\u003ch2\u003e参数\u003c/h2\u003e\u003cdiv\u003e\u003cdl\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003etable_name.column_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eaggregate_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003efunction_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eprocedure_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eroutine_name\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e要加上安全标签的对象名称。位于模式中的对象（表、函数等）的名称可以带模式限定。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eprovider\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e要与该标签关联的标签提供者名称。指定的提供者必须已加载，并且必须同意所提议的标签设置操作。若只加载了一个提供者，则为简洁起见可以省略其名称。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的模式：\u003ccode\u003eIN\u003c/code\u003e、\u003ccode\u003eOUT\u003c/code\u003e、\u003ccode\u003eINOUT\u003c/code\u003e或\u003ccode\u003eVARIADIC\u003c/code\u003e。如果省略，默认值是 \u003ccode\u003eIN\u003c/code\u003e。注意\u003ccode\u003eSECURITY LABEL\u003c/code\u003e实际上并不关心\u003ccode\u003eOUT\u003c/code\u003e参数，因为确定函数身份只需要输入参数。因此，列出 \u003ccode\u003eIN\u003c/code\u003e、\u003ccode\u003eINOUT\u003c/code\u003e和\u003ccode\u003eVARIADIC\u003c/code\u003e参数就足够了。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的名称。注意\u003ccode\u003eSECURITY LABEL\u003c/code\u003e 实际上并不关心参数名称，因为确定函数身份只需要参数数据类型。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的数据类型。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003elarge_object_oid\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e大对象的 OID。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003ccode\u003ePROCEDURAL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e这是一个噪声词。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003cem\u003e\u003ccode\u003estring_literal\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e安全标签的新值，以字符串字面量形式写出。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eNULL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e写入\u003ccode\u003eNULL\u003c/code\u003e可删除安全标签。\u003c/p\u003e\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e\u003c/section\u003e\u003csection\u003e\u003ch2\u003e示例\u003c/h2\u003e\u003cp\u003e下面的示例展示了如何设置或更改一个表的安全标签：\u003c/p\u003e\u003cpre\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS \u0026#39;system_u:object_r:sepgsql_table_t:s0\u0026#39;;\n\u003c/pre\u003e\u003cp\u003e要移除该标签：\u003c/p\u003e\u003cpre\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS NULL;\n\u003c/pre\u003e\u003c/section\u003e\u003csection\u003e\u003ch2\u003e兼容性\u003c/h2\u003e\u003cp\u003e在 SQL 标准中没有\u003ccode\u003eSECURITY LABEL\u003c/code\u003e命令。\u003c/p\u003e\u003c/section\u003e\u003csection\u003e\u003ch2\u003e另见\u003c/h2\u003e\u003cspan\u003e\u003ca href=\"/docs/18/sepgsql.html\" rel=\"nofollow\"\u003esepgsql\u003c/a\u003e, \u003ccode\u003esrc/test/modules/dummy_seclabel\u003c/code\u003e\u003c/span\u003e\u003c/section\u003e","SourceRevision":"ca936764","ContentHash":"63b3a5ca8187d7372bcd34b6c793a988f2b004b15b2cce6a4fe884b6430cbc05","Payload":{"purpose_zh":"定义或更改应用于对象的安全标签","sections":[{"html":"\u003cp\u003e\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e为数据库对象设置安全标签。一个给定的数据库对象可以关联任意数量的安全标签，每个标签提供者对应一个。标签提供者是使用函数\u003ccode class=\"function\"\u003eregister_label_provider\u003c/code\u003e注册自身的可加载模块。\u003c/p\u003e\u003cdiv class=\"note\"\u003e\u003ch3\u003e注意\u003c/h3\u003e\u003cp\u003e\u003ccode class=\"function\"\u003eregister_label_provider\u003c/code\u003e不是一个 SQL 函数；它只能从加载到后端的 C 代码中调用。\u003c/p\u003e\u003c/div\u003e\u003cp\u003e标签提供者决定给定标签是否有效，以及是否允许将该标签赋给给定对象。给定标签的含义同样由标签提供者自行决定。\u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e不限制标签提供者是否解释安全标签，也不限制其如何解释；它仅提供一种存储安全标签的机制。实际上，此功能旨在支持与基于标签的强制访问控制（MAC）系统（例如\u003cspan class=\"productname\"\u003eSELinux\u003c/span\u003e）集成。这类系统基于对象标签，而不是基于用户和组等传统的自主访问控制（DAC）概念，做出所有访问控制决策。\u003c/p\u003e\u003cp\u003e要使用\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e，你必须拥有该数据库对象。\u003c/p\u003e","key":"description","title":"描述"},{"html":"\u003cdiv class=\"variablelist\"\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003etable_name.column_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003efunction_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eprocedure_name\u003c/code\u003e\u003c/em\u003e\u003cbr\u003e\u003c/span\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eroutine_name\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e要加上安全标签的对象名称。位于模式中的对象（表、函数等）的名称可以带模式限定。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eprovider\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e要与该标签关联的标签提供者名称。指定的提供者必须已加载，并且必须同意所提议的标签设置操作。若只加载了一个提供者，则为简洁起见可以省略其名称。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的模式：\u003ccode class=\"literal\"\u003eIN\u003c/code\u003e、\u003ccode class=\"literal\"\u003eOUT\u003c/code\u003e、\u003ccode class=\"literal\"\u003eINOUT\u003c/code\u003e或\u003ccode class=\"literal\"\u003eVARIADIC\u003c/code\u003e。如果省略，默认值是 \u003ccode class=\"literal\"\u003eIN\u003c/code\u003e。注意\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e实际上并不关心\u003ccode class=\"literal\"\u003eOUT\u003c/code\u003e参数，因为确定函数身份只需要输入参数。因此，列出 \u003ccode class=\"literal\"\u003eIN\u003c/code\u003e、\u003ccode class=\"literal\"\u003eINOUT\u003c/code\u003e和\u003ccode class=\"literal\"\u003eVARIADIC\u003c/code\u003e参数就足够了。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的名称。注意\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e 实际上并不关心参数名称，因为确定函数身份只需要参数数据类型。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e函数、过程或聚合函数参数的数据类型。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003elarge_object_oid\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e大对象的 OID。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003ePROCEDURAL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e这是一个噪声词。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003estring_literal\u003c/code\u003e\u003c/em\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e安全标签的新值，以字符串字面量形式写出。\u003c/p\u003e\u003c/dd\u003e\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eNULL\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\u003cdd\u003e\u003cp\u003e写入\u003ccode class=\"literal\"\u003eNULL\u003c/code\u003e可删除安全标签。\u003c/p\u003e\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","key":"parameters","title":"参数"},{"html":"\u003cp\u003e下面的示例展示了如何设置或更改一个表的安全标签：\u003c/p\u003e\u003cpre class=\"programlisting\"\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS 'system_u:object_r:sepgsql_table_t:s0';\n\u003c/pre\u003e\u003cp\u003e要移除该标签：\u003c/p\u003e\u003cpre class=\"programlisting\"\u003eSECURITY LABEL FOR selinux ON TABLE mytable IS NULL;\n\u003c/pre\u003e","key":"examples","title":"示例"},{"html":"\u003cp\u003e在 SQL 标准中没有\u003ccode class=\"command\"\u003eSECURITY LABEL\u003c/code\u003e命令。\u003c/p\u003e","key":"compatibility","title":"兼容性"},{"html":"\u003cspan class=\"simplelist\"\u003e\u003ca href=\"/docs/18/sepgsql.html\" title=\"F.40. sepgsql — 基于 SELinux 标签的强制访问控制（MAC）安全模块\"\u003esepgsql\u003c/a\u003e, \u003ccode class=\"filename\"\u003esrc/test/modules/dummy_seclabel\u003c/code\u003e\u003c/span\u003e","key":"see_also","title":"另见"}],"sections_same_as":"","synopsis_html":"SECURITY LABEL [ FOR \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprovider\u003c/code\u003e\u003c/em\u003e ] ON\n{\n  TABLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  COLUMN \u003cem class=\"replaceable\"\u003e\u003ccode\u003etable_name\u003c/code\u003e\u003c/em\u003e.\u003cem class=\"replaceable\"\u003e\u003ccode\u003ecolumn_name\u003c/code\u003e\u003c/em\u003e |\n  AGGREGATE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_name\u003c/code\u003e\u003c/em\u003e ( \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_signature\u003c/code\u003e\u003c/em\u003e ) |\n  DATABASE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  DOMAIN \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  EVENT TRIGGER \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  FOREIGN TABLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  FUNCTION \u003cem class=\"replaceable\"\u003e\u003ccode\u003efunction_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  LARGE OBJECT \u003cem class=\"replaceable\"\u003e\u003ccode\u003elarge_object_oid\u003c/code\u003e\u003c/em\u003e |\n  MATERIALIZED VIEW \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  [ PROCEDURAL ] LANGUAGE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  PROCEDURE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprocedure_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  PUBLICATION \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  ROLE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  ROUTINE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eroutine_name\u003c/code\u003e\u003c/em\u003e [ ( [ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [, ...] ] ) ] |\n  SCHEMA \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  SEQUENCE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  SUBSCRIPTION \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  TABLESPACE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  TYPE \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e |\n  VIEW \u003cem class=\"replaceable\"\u003e\u003ccode\u003eobject_name\u003c/code\u003e\u003c/em\u003e\n} IS { \u003cem class=\"replaceable\"\u003e\u003ccode\u003estring_literal\u003c/code\u003e\u003c/em\u003e | NULL }\n\n\u003cspan class=\"phrase\"\u003e其中 \u003cem class=\"replaceable\"\u003e\u003ccode\u003eaggregate_signature\u003c/code\u003e\u003c/em\u003e 是：\u003c/span\u003e\n\n* |\n[ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ] |\n[ [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ] ] ORDER BY [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargmode\u003c/code\u003e\u003c/em\u003e ] [ \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargname\u003c/code\u003e\u003c/em\u003e ] \u003cem class=\"replaceable\"\u003e\u003ccode\u003eargtype\u003c/code\u003e\u003c/em\u003e [ , ... ]","synopsis_text":"SECURITY LABEL [ FOR provider ] ON\n{\nTABLE object_name |\nCOLUMN table_name.column_name |\nAGGREGATE aggregate_name ( aggregate_signature ) |\nDATABASE object_name |\nDOMAIN object_name |\nEVENT TRIGGER object_name |\nFOREIGN TABLE object_name |\nFUNCTION function_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nLARGE OBJECT large_object_oid |\nMATERIALIZED VIEW object_name |\n[ PROCEDURAL ] LANGUAGE object_name |\nPROCEDURE procedure_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nPUBLICATION object_name |\nROLE object_name |\nROUTINE routine_name [ ( [ [ argmode ] [ argname ] argtype [, ...] ] ) ] |\nSCHEMA object_name |\nSEQUENCE object_name |\nSUBSCRIPTION object_name |\nTABLESPACE object_name |\nTYPE object_name |\nVIEW object_name\n} IS { string_literal | NULL }\n\n其中 aggregate_signature 是：\n\n* |\n[ argmode ] [ argname ] argtype [ , ... ] |\n[ [ argmode ] [ argname ] argtype [ , ... ] ] ORDER BY [ argmode ] [ argname ] argtype [ , ... ]"}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
