Review Request: JDK-8182137: Missing permissions in deprivileged java.xml.bind and java.xml.ws modules
Mandy Chung
mandy.chung at oracle.com
Wed Jun 14 15:11:35 UTC 2017
http://cr.openjdk.java.net/~mchung/jdk9/webrevs/8182137/webrev.00/
java.xml.bind and java.xml.ws modules are deprivileged and granted with specific permissions since jdk-9+51. JAXB and JAX-WS tests were ran and found no regressions when security manager is enabled. It is recently uncovered that FilePermission is missing from JAXB and RuntimePermission("createClassLoader") is missing from JAX-WS. We have uncovered that the test policy file used by JAXB and JAX-WS tests grant permissions to the default code source that masks this problem.
At this late stage in JDK 9, we propose to grant java.xml.bind and java.xml.bind with AllPermissions which is same as JDK 8. These modules are still deprivileged and defined to the platform class loader.
Mandy
More information about the core-libs-dev
mailing list