java - jar 未在启用 java.security.manager 的情况下加载

标签 java java-security java-security-manager

我们运行一个 spring-boot 应用程序,它将在/tmp 文件夹中动态下载一些 jar 并在这些 jar 中执行一些功能。

现在我们已经启用了 java.security.manager 并在 security.policy 文件中给出了以下策略。

以下是 security.policy 文件中指定的策略

// These permissions apply to javac
grant codeBase "file:${java.home}/lib/-" {
        permission java.security.AllPermission;
};

// These permissions apply to all shared system extensions
grant codeBase "file:${java.home}/jre/lib/ext/-" {
        permission java.security.AllPermission;
};

// These permissions apply to javac when ${java.home] points at $JAVA_HOME/jre
grant codeBase "file:${java.home}/../lib/-" {
        permission java.security.AllPermission;
};

// These permissions apply to all shared system extensions when
// ${java.home} points at $JAVA_HOME/jre
grant codeBase "file:${java.home}/lib/ext/-" {
        permission java.security.AllPermission;
};

// aml jar permission
grant codeBase "file:/app.jar"{
        permission java.security.AllPermission;
};

grant codeBase "file:/tmp/-"{
           permission java.io.FilePermission "/tmp/*", "read,write";
           permission java.lang.RunTimePermission "createClassLoader";
           permission java.lang.RunTimePermission "getClassLoader";
           permission java.lang.RunTimePermission "setContextClassLoader";
           permission java.lang.RunTimePermission "enableContextClassLoaderOverride";
           permission java.lang.RunTimePermission "createSecurityManager";
           permission java.lang.RunTimePermission "setSecurityManager";
               permission java.lang.RunTimePermission "getProtectionDomain";
               permission java.lang.RunTimePermission "readFileDescriptor";
               permission java.lang.RunTimePermission "writeFileDescriptor";
               permission java.lang.RunTimePermission "loadLibrary.libraryName";
               permission java.lang.RunTimePermission "setFactory";
               permission java.lang.RunTimePermission "setIO";
               permission java.lang.RunTimePermission "loadLibrary.*";
};


// ========== WEB APPLICATION PERMISSIONS =====================================


// These permissions are granted by default to all web applications
// In addition, a web application will be given a read FilePermission
// and JndiPermission for all files and directories in its document root.
grant {
    // Required for JNDI lookup of named JDBC DataSource's and
    // javamail named MimePart DataSource used to send mail
    permission java.util.PropertyPermission "java.home", "read";
    permission java.util.PropertyPermission "java.naming.*", "read";
    permission java.util.PropertyPermission "javax.sql.*", "read";

    // OS Specific properties to allow read access
    permission java.util.PropertyPermission "os.name", "read";
    permission java.util.PropertyPermission "os.version", "read";
    permission java.util.PropertyPermission "os.arch", "read";
    permission java.util.PropertyPermission "file.separator", "read";
    permission java.util.PropertyPermission "path.separator", "read";
    permission java.util.PropertyPermission "line.separator", "read";

    // JVM properties to allow read access
    permission java.util.PropertyPermission "java.version", "read";
    permission java.util.PropertyPermission "java.vendor", "read";
    permission java.util.PropertyPermission "java.vendor.url", "read";
    permission java.util.PropertyPermission "java.class.version", "read";
    permission java.util.PropertyPermission "java.specification.version", "read";
    permission java.util.PropertyPermission "java.specification.vendor", "read";
    permission java.util.PropertyPermission "java.specification.name", "read";

    permission java.util.PropertyPermission "java.vm.specification.version", "read";
    permission java.util.PropertyPermission "java.vm.specification.vendor", "read";
    permission java.util.PropertyPermission "java.vm.specification.name", "read";
    permission java.util.PropertyPermission "java.vm.version", "read";
    permission java.util.PropertyPermission "java.vm.vendor", "read";
    permission java.util.PropertyPermission "java.vm.name", "read";


};

并且一些 jar 在内部加载/tmp 文件夹中的另一个 jar。使用这些策略,我们无法加载这些 jar 。

有人可以帮助我们吗

最佳答案

我想这可能对你有帮助......

https://www.ibm.com/support/knowledgecenter/en/SSEQTP_9.0.0/com.ibm.websphere.base.doc/ae/rsec_javapolicy.html

java.security.AccessControlException:访问被拒绝(java.io.FilePermission C:\WebSphere\AppServer\java\jre\lib\ext\mail.jar 读取)

关于java - jar 未在启用 java.security.manager 的情况下加载,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/56785359/

相关文章:

java - HSM:使用 JAVA 应用程序引入 HSM

ssl - 启用 TLSv1.2 和 TLS_RSA_WITH_AES_256_CBC_SHA256 密码套件

Java Json 到列表列表

java - 解析 XML 时拦截 Xstream

java - 这段 Java 1.7 代码片段中的 TLS 版本是什么?

java - JVM - Java 虚拟机损坏

java - 在openjdk中,安全策略没有生效

java - 线程 "ContainerBackgroundProcessor[StandardEngine[Tomcat]]"java.lang.NoClassDefFoundError : ch/qos/logback/classic/spi/ThrowableProxy 中出现异常

java - 将整数对象转换为原始类型时遇到问题

java - 如果相同的方法重载和覆盖,Java 中的意外多态行为