0P000 — 角色规范无效(invalid_role_specification)
角色规范无效,指定的角色不可用。
英文手册覆盖始于 PostgreSQL 8.1. 来源历史与运行验证各自保留独立版本边界。
当前阅读 PG 18·选择有来源记录的版本
- aliases
- 未知
- class name
- Invalid Role Specification
- condition name
- invalid_role_specification
- lang
- en
- sqlstate
- 0P000
版本定义 PG 18
0P000 — 角色规范无效
速览 {#at-a-glance}
SQLSTATE 0P000 是 Class 0P 中的 invalid_role_specification。在 ENABLE_SSPI 下,固定的 Windows SSPI 路径在把 SAM 账户名转换为 UPN 时以服务器 LOG 分支使用它;它不是普通的“角色不存在”登录结果,也不是客户端 ErrorResponse。
含义 {#meaning}
0P000 是 invalid_role_specification。固定的 pg_SSPI_make_upn 路径构造 DOMAIN\user,调用 Windows TranslateName 得到 user@realm;转换失败、结果没有 @,或 realm/账户无法放入目标缓冲区时记录 0P000。这些是 ENABLE_SSPI 下的服务器 LOG 分支,不是客户端 ErrorResponse,也不是普通角色缺失结果。
诊断 {#diagnosis}
确认失败路径确实是 Windows SSPI,并结合服务器日志检查 SAM 账户/域名及配置的 realm 或 UPN 映射。TranslateName 失败(包括结果不含 @)记录 could not translate name;realm 过长记录 realm name too long;转换后的账户过长记录 translated account name too long。使用 trust 认证的临时实例无法忠实演示这一外部身份边界;启动 ErrorResponse 也可能是 28000 或 28P01。
处理 {#response}
修复 SSPI 账户/realm 映射或 Windows 名称转换配置后建立新连接。应把这些服务器日志诊断与启动认证响应、SQL 角色不存在和密码失败分开。
报文 {#messages}
固定 SSPI 源码以 LOG 和 SQLSTATE 0P000 记录以下主报文模板:could not translate name、realm name too long、translated account name too long。这些是服务器日志记录;只有客户端异常或没有匹配服务器日志的启动 ErrorResponse,都不能证明 0P000。
代表案例 {#case}
本页没有选定的自然 SQL 运行。结构化证据记录的是源码或定义边界;客户端 RAISE 不能代表服务器机制。
版本 {#versions}
上面的生成事实表记录锁定的目录快照和最早观察到的定义。本页没有选定的自然 SQL 运行;固定 REL_18_6/REL_10_23 的 SSPI 源码比较不能当作实测结果,也不能据此推断所有中间版本的行为。
相关 {#related}
来源 {#sources}
src.auth-name-translation.18.6—src/backend/libpq/auth.catREL_18_6commit724edf9bde9d356724ad384a2e196edc3c9f80f7; fixed blob SHA-25694252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1(source).src.auth-name-translation.10.23—src/backend/libpq/auth.catREL_10_23commit02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4; fixed blob SHA-25615418faa6d6ee1b2a4ad1e50ebc9b34c2daf4799f7062df425e33dbf777ade61(source).src.auth-sspi-upn.10.23—src/backend/libpq/auth.catREL_10_23commit02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4; fixed blob SHA-25615418faa6d6ee1b2a4ad1e50ebc9b34c2daf4799f7062df425e33dbf777ade61(source).src.calls.REL_18_6/src.calls.REL_10_23— fixed local call scans, SHA-2569ee8a0e81d8f0825c5c1ae45583439859a26e602bdd4ce2f2a62aa278867ccbf/00d16d3eb01b71ccf1b245c8f3102f9d0ec9f36fb02777b8dd1b99fcb263040c; these scans preserve the resolved call context used by the claims.
比较版本
SQLSTATE 证据与已记录的运行版本
cases · source_boundary
{
"assertions": [],
"case_id": "source_boundary",
"cleanup": "Drop the case schema with an owner connection.",
"has_snippet": false,
"position": 0,
"preconditions": [
"A runner-owned disposable target is provisioned only if a source-boundary smoke run is requested."
],
"repair": "Use the concrete source path or component-specific documentation when it applies.",
"trigger": "No artificial SQL trigger is executed; this record preserves the fixed source/definition boundary.",
"versions": [
"10",
"18"
]
}claims · identity.class-and-condition
{
"claim_id": "identity.class-and-condition",
"limits": "Directory identity does not identify every backend or client path.",
"method": "Read the fixed errcodes.txt definition and the locked catalogue metadata.",
"position": 0,
"runtime": [],
"sources": [
"src.errcodes.18.6"
],
"statement": "0P000 is the invalid_role_specification condition in Class 0P."
}claims · mechanism.source-boundary
{
"claim_id": "mechanism.source-boundary",
"limits": "This is a bounded source claim under ENABLE_SSPI; the disposable trust target cannot faithfully exercise it, and it is not an observed natural SQLSTATE case.",
"method": "Read the complete fixed SSPI authentication and pg_SSPI_make_upn paths in REL_18_6 and REL_10_23, including each explicit LOG branch.",
"position": 1,
"runtime": [],
"sources": [
"src.auth-name-translation.18.6",
"src.auth-name-translation.10.23",
"src.auth-sspi-upn.10.23"
],
"statement": "Under ENABLE_SSPI, the fixed pg_SSPI_make_upn path builds a DOMAIN\\user SAM name, calls Windows TranslateName to obtain a user@realm UPN, and logs 0P000 when translation fails, the result has no @, or the realm or translated account exceeds its target buffer. These are server LOG branches, not client ErrorResponse fields."
}claims · versions.catalogue-boundary
{
"claim_id": "versions.catalogue-boundary",
"limits": "Presence in a definition file is not an exact behavioral introduction, and the fixed source paths do not prove every intermediate release or authentication configuration.",
"method": "Read the generated facts block and fixed SSPI source records; no runtime result is used for this source-only page.",
"position": 2,
"runtime": [],
"sources": [
"src.errcodes.18.6",
"src.auth-name-translation.18.6",
"src.auth-sspi-upn.10.23"
],
"statement": "The locked catalogue records 0P000 in the listed snapshots; this page compares only the fixed REL_18_6 and REL_10_23 SSPI source paths and has no selected natural runtime."
}messages · message.auth-name-translation
{
"limits": "",
"message_id": "message.auth-name-translation",
"path": "",
"position": 0,
"raw": {
"id": "message.auth-name-translation",
"primary_template": "could not translate name",
"severity_source": "LOG",
"sources": [
"src.auth-name-translation.18.6",
"src.auth-name-translation.10.23",
"src.auth-sspi-upn.10.23"
],
"sqlstate": "0P000"
},
"severity": "LOG",
"sources": [
"src.auth-name-translation.18.6",
"src.auth-name-translation.10.23",
"src.auth-sspi-upn.10.23"
],
"templates": [
{
"kind": "primary",
"literal": "could not translate name",
"position": 0,
"role": "",
"template": "could not translate name"
}
]
}messages · message.auth-sspi-realm-too-long
{
"limits": "",
"message_id": "message.auth-sspi-realm-too-long",
"path": "",
"position": 1,
"raw": {
"id": "message.auth-sspi-realm-too-long",
"primary_template": "realm name too long",
"severity_source": "explicit LOG",
"sources": [
"src.auth-sspi-upn.10.23"
],
"sqlstate": "0P000"
},
"severity": "explicit LOG",
"sources": [
"src.auth-sspi-upn.10.23"
],
"templates": [
{
"kind": "primary",
"literal": "realm name too long",
"position": 0,
"role": "",
"template": "realm name too long"
}
]
}messages · message.auth-sspi-account-too-long
{
"limits": "",
"message_id": "message.auth-sspi-account-too-long",
"path": "",
"position": 2,
"raw": {
"id": "message.auth-sspi-account-too-long",
"primary_template": "translated account name too long",
"severity_source": "explicit LOG",
"sources": [
"src.auth-sspi-upn.10.23"
],
"sqlstate": "0P000"
},
"severity": "explicit LOG",
"sources": [
"src.auth-sspi-upn.10.23"
],
"templates": [
{
"kind": "primary",
"literal": "translated account name too long",
"position": 0,
"role": "",
"template": "translated account name too long"
}
]
}sources · src.errcodes.18.6
{
"commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
"docs_url": "",
"kind": "upstream_source",
"location": "",
"path": "src/backend/utils/errcodes.txt",
"position": 0,
"sha256": "6e8de346643ba84aa3c9c6a73360acfc7b2dfb89162c06c08ce9bf5bcd5bbcba",
"source_id": "src.errcodes.18.6",
"tag": "REL_18_6",
"url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/errcodes.txt"
}sources · src.calls.REL_18_6
{
"commit": "",
"docs_url": "",
"kind": "local_artifact",
"location": "",
"path": "raw/calls/REL_18_6.jsonl",
"position": 1,
"sha256": "9ee8a0e81d8f0825c5c1ae45583439859a26e602bdd4ce2f2a62aa278867ccbf",
"source_id": "src.calls.REL_18_6",
"tag": "REL_18_6",
"url": ""
}sources · src.calls.REL_10_23
{
"commit": "",
"docs_url": "",
"kind": "local_artifact",
"location": "",
"path": "raw/calls/REL_10_23.jsonl",
"position": 2,
"sha256": "00d16d3eb01b71ccf1b245c8f3102f9d0ec9f36fb02777b8dd1b99fcb263040c",
"source_id": "src.calls.REL_10_23",
"tag": "REL_10_23",
"url": ""
}sources · src.auth-name-translation.18.6
{
"commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
"docs_url": "",
"kind": "upstream_source",
"location": "",
"path": "src/backend/libpq/auth.c",
"position": 3,
"sha256": "94252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1",
"source_id": "src.auth-name-translation.18.6",
"tag": "REL_18_6",
"url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/libpq/auth.c#L1514-L1516"
}sources · src.auth-name-translation.10.23
{
"commit": "02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4",
"docs_url": "",
"kind": "upstream_source",
"location": "",
"path": "src/backend/libpq/auth.c",
"position": 4,
"sha256": "15418faa6d6ee1b2a4ad1e50ebc9b34c2daf4799f7062df425e33dbf777ade61",
"source_id": "src.auth-name-translation.10.23",
"tag": "REL_10_23",
"url": "https://github.com/postgres/postgres/blob/02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4/src/backend/libpq/auth.c#L1699-L1701"
}sources · src.auth-sspi-upn.10.23
{
"commit": "02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4",
"docs_url": "",
"kind": "upstream_source",
"location": "",
"path": "src/backend/libpq/auth.c",
"position": 5,
"sha256": "15418faa6d6ee1b2a4ad1e50ebc9b34c2daf4799f7062df425e33dbf777ade61",
"source_id": "src.auth-sspi-upn.10.23",
"tag": "REL_10_23",
"url": "https://github.com/postgres/postgres/blob/02991e79f8f58bc208f05dcc8af0c62dbe0a6ea4/src/backend/libpq/auth.c#L1666-L1758"
}sources · manifest.0P000
{
"commit": "",
"docs_url": "",
"kind": "local_artifact",
"location": "",
"path": "verify/cases/0P000/cases.json",
"position": 6,
"sha256": "2460d980be19d06e88766a7907f6f3a301ae4786dcab8c019736a904116aadc4",
"source_id": "manifest.0P000",
"tag": "workspace",
"url": "verify/cases/0P000/cases.json"
}来源引用
定义来源
center · PostgreSQL 18 · english-manuals:b11b2ee2355ba4563d32ab458ec76cfcacc50f2d295a1f03001d1e560698cc19
正文语言: zh-Hans · english-manuals:b11b2ee2355ba4563d32ab458ec76cfcacc50f2d295a1f03001d1e560698cc19