src/jdk.jfr/share/classes/jdk/jfr/internal/WriteableUserPath.java
author egahlin
Thu, 06 Jun 2019 15:22:12 +0200
changeset 55256 3b22c7e00573
parent 50113 caf115bb98ad
permissions -rw-r--r--
8224217: RecordingInfo should use textual representation of path Reviewed-by: mgronlun
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     1
/*
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     2
 * Copyright (c) 2016, 2018, Oracle and/or its affiliates. All rights reserved.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     4
 *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     7
 * published by the Free Software Foundation.  Oracle designates this
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
     9
 * by Oracle in the LICENSE file that accompanied this code.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    10
 *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    15
 * accompanied this code).
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    16
 *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    20
 *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    21
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    22
 * or visit www.oracle.com if you need additional information or have any
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    23
 * questions.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    24
 */
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    25
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    26
package jdk.jfr.internal;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    27
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    28
import java.io.BufferedWriter;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    29
import java.io.FileNotFoundException;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    30
import java.io.IOException;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    31
import java.nio.file.Files;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    32
import java.nio.file.Path;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    33
import java.security.AccessControlContext;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    34
import java.security.AccessController;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    35
import java.security.PrivilegedExceptionAction;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    36
import java.util.concurrent.Callable;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    37
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    38
/**
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    39
 * Purpose of this class is to simplify analysis of security risks.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    40
 * <p>
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    41
 * Paths in the public API should be wrapped in this class so we
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    42
 * at all time know what kind of paths we are dealing with.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    43
 * <p>
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    44
 * A user supplied path must never be used in an unsafe context, such as a
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    45
 * shutdown hook or any other thread created by JFR.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    46
 * <p>
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    47
 * All operation using this path must happen in {@link #doPriviligedIO(Callable)}
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    48
 */
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    49
public final class WriteableUserPath {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    50
    private final AccessControlContext controlContext;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    51
    private final Path original;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    52
    private final Path real;
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    53
    private final String realPathText;
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    54
    private final String originalText;
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    55
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    56
    // Not to ensure security, but to help
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    57
    // against programming errors
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    58
    private volatile boolean inPrivileged;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    59
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    60
    public WriteableUserPath(Path path) throws IOException {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    61
        controlContext = AccessController.getContext();
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    62
        // verify that the path is writeable
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    63
        if (Files.exists(path) && !Files.isWritable(path)) {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    64
            // throw same type of exception as FileOutputStream
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    65
            // constructor, if file can't be opened.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    66
            throw new FileNotFoundException("Could not write to file: " + path.toAbsolutePath());
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    67
        }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    68
        // will throw if non-writeable
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    69
        BufferedWriter fw = Files.newBufferedWriter(path);
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    70
        fw.close();
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    71
        this.original = path;
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    72
        this.originalText = path.toString();
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    73
        this.real = path.toRealPath();
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    74
        this.realPathText = real.toString();
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    75
    }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    76
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    77
    /**
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    78
     * Returns a potentially malicious path where the user may have implemented
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    79
     * their own version of Path. This method should never be called in an
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    80
     * unsafe context and the Path value should never be passed along to other
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    81
     * methods.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    82
     *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    83
     * @return path from a potentially malicious user
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    84
     */
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    85
    public Path getPotentiallyMaliciousOriginal() {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    86
        return original;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    87
    }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    88
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    89
    /**
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    90
     * Returns a string representation of the real path.
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    91
     *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    92
     * @return path as text
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    93
     */
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    94
    public String getRealPathText() {
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    95
        return realPathText;
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    96
    }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    97
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
    98
    /**
55256
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
    99
     * Returns a string representation of the original path.
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   100
     *
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   101
     * @return path as text
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   102
     */
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   103
    public String getOriginalText() {
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   104
        return originalText;
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   105
    }
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   106
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   107
3b22c7e00573 8224217: RecordingInfo should use textual representation of path
egahlin
parents: 50113
diff changeset
   108
    /**
50113
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   109
     * Returns a potentially malicious path where the user may have implemented
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   110
     * their own version of Path. This method should never be called in an
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   111
     * unsafe context and the Path value should never be passed along to other
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   112
     * methods.
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   113
     *
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   114
     * @return path from a potentially malicious user
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   115
     */
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   116
    public Path getReal() {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   117
        if (!inPrivileged) {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   118
            throw new InternalError("A user path was accessed outside the context it was supplied in");
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   119
        }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   120
        return real;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   121
    }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   122
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   123
    public void doPriviligedIO(Callable<?> function) throws IOException {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   124
        try {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   125
            inPrivileged = true;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   126
            AccessController.doPrivileged(new PrivilegedExceptionAction<Void>() {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   127
                @Override
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   128
                public Void run() throws Exception {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   129
                    function.call();
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   130
                    return null;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   131
                }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   132
            }, controlContext);
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   133
        } catch (Throwable t) {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   134
            // prevent malicious user to propagate exception callback
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   135
            // in the wrong context
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   136
            throw new IOException("Unexpected error during I/O operation");
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   137
        } finally {
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   138
            inPrivileged = false;
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   139
        }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   140
    }
caf115bb98ad 8199712: Flight Recorder
egahlin
parents:
diff changeset
   141
}