我们运行一个 spring-boot 应用程序,它将在 /tmp 文件夹中动态下载一些 jars 并在这些 jars 中执行一些功能。
现在我们启用了 java.security.manager 并在 security.policy 文件中给出了以下策略。
以下是 security.policy 文件中指定的策略
// These permissions apply to javac
grant codeBase "file:${java.home}/lib/-" {
permission java.security.AllPermission;
};
// These permissions apply to all shared system extensions
grant codeBase "file:${java.home}/jre/lib/ext/-" {
permission java.security.AllPermission;
};
// These permissions apply to javac when ${java.home] points at $JAVA_HOME/jre
grant codeBase "file:${java.home}/../lib/-" {
permission java.security.AllPermission;
};
// These permissions apply to all shared system extensions when
// ${java.home} points at $JAVA_HOME/jre
grant codeBase "file:${java.home}/lib/ext/-" {
permission java.security.AllPermission;
};
// aml jar permission
grant codeBase "file:/app.jar"{
permission java.security.AllPermission;
};
grant codeBase "file:/tmp/-"{
permission java.io.FilePermission "/tmp/*", "read,write";
permission java.lang.RunTimePermission "createClassLoader";
permission java.lang.RunTimePermission "getClassLoader";
permission java.lang.RunTimePermission "setContextClassLoader";
permission java.lang.RunTimePermission "enableContextClassLoaderOverride";
permission java.lang.RunTimePermission "createSecurityManager";
permission java.lang.RunTimePermission "setSecurityManager";
permission java.lang.RunTimePermission "getProtectionDomain";
permission java.lang.RunTimePermission "readFileDescriptor";
permission java.lang.RunTimePermission "writeFileDescriptor";
permission java.lang.RunTimePermission "loadLibrary.libraryName";
permission java.lang.RunTimePermission "setFactory";
permission java.lang.RunTimePermission "setIO";
permission java.lang.RunTimePermission "loadLibrary.*";
};
// ========== WEB APPLICATION PERMISSIONS =====================================
// These permissions are granted by default to all web applications
// In addition, a web application will be given a read FilePermission
// and JndiPermission for all files and directories in its document root.
grant {
// Required for JNDI lookup of named JDBC DataSource's and
// javamail named MimePart DataSource used to send mail
permission java.util.PropertyPermission "java.home", "read";
permission java.util.PropertyPermission "java.naming.*", "read";
permission java.util.PropertyPermission "javax.sql.*", "read";
// OS Specific properties to allow read access
permission java.util.PropertyPermission "os.name", "read";
permission java.util.PropertyPermission "os.version", "read";
permission java.util.PropertyPermission "os.arch", "read";
permission java.util.PropertyPermission "file.separator", "read";
permission java.util.PropertyPermission "path.separator", "read";
permission java.util.PropertyPermission "line.separator", "read";
// JVM properties to allow read access
permission java.util.PropertyPermission "java.version", "read";
permission java.util.PropertyPermission "java.vendor", "read";
permission java.util.PropertyPermission "java.vendor.url", "read";
permission java.util.PropertyPermission "java.class.version", "read";
permission java.util.PropertyPermission "java.specification.version", "read";
permission java.util.PropertyPermission "java.specification.vendor", "read";
permission java.util.PropertyPermission "java.specification.name", "read";
permission java.util.PropertyPermission "java.vm.specification.version", "read";
permission java.util.PropertyPermission "java.vm.specification.vendor", "read";
permission java.util.PropertyPermission "java.vm.specification.name", "read";
permission java.util.PropertyPermission "java.vm.version", "read";
permission java.util.PropertyPermission "java.vm.vendor", "read";
permission java.util.PropertyPermission "java.vm.name", "read";
};
并且一些罐子在内部加载 /tmp 文件夹中的另一个罐子。使用这些政策,我们无法加载这些罐子。
有人可以帮助我们吗