jdk/src/java.base/share/conf/security/java.policy
author msheppar
Mon, 16 Feb 2015 00:10:42 +0000
changeset 28967 7a1ceff4aea2
parent 28849 ccf9d86e52ec
child 31268 63fcde3b5c3b
permissions -rw-r--r--
8068682: Deprivilege/move java.corba to the ext class loader Reviewed-by: alanb, mchung
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
     1
// permissions required by each component
28967
7a1ceff4aea2 8068682: Deprivilege/move java.corba to the ext class loader
msheppar
parents: 28849
diff changeset
     2
grant codeBase "jrt:/java.corba" {
7a1ceff4aea2 8068682: Deprivilege/move java.corba to the ext class loader
msheppar
parents: 28849
diff changeset
     3
        permission java.security.AllPermission;
7a1ceff4aea2 8068682: Deprivilege/move java.corba to the ext class loader
msheppar
parents: 28849
diff changeset
     4
};
7a1ceff4aea2 8068682: Deprivilege/move java.corba to the ext class loader
msheppar
parents: 28849
diff changeset
     5
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
     6
grant codeBase "jrt:/jdk.zipfs" {
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
     7
        permission java.io.FilePermission "<<ALL FILES>>", "read,write,delete";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
     8
        permission java.lang.RuntimePermission "fileSystemProvider";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
     9
        permission java.util.PropertyPermission "*", "read";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    10
};
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    11
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    12
grant codeBase "jrt:/jdk.localedata" {
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    13
        permission java.lang.RuntimePermission "accessClassInPackage.sun.text.*";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    14
        permission java.lang.RuntimePermission "accessClassInPackage.sun.util.*";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    15
        permission java.util.PropertyPermission "*", "read";
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    16
};
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    17
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    18
grant codeBase "jrt:/jdk.naming.dns" {
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    19
        permission java.security.AllPermission;
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    20
};
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    21
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    22
grant codeBase "jrt:/jdk.scripting.nashorn" {
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    23
        permission java.security.AllPermission;
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    24
};
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    25
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    26
grant codeBase "jrt:/jdk.crypto.ucrypto" {
27182
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    27
        permission java.lang.RuntimePermission "accessClassInPackage.sun.security.*";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    28
        permission java.lang.RuntimePermission "accessClassInPackage.sun.nio.ch";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    29
        permission java.lang.RuntimePermission "loadLibrary.j2ucrypto";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    30
        // need "com.oracle.security.ucrypto.debug" for debugging
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    31
        permission java.util.PropertyPermission "*", "read";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    32
        permission java.security.SecurityPermission "putProviderProperty.OracleUcrypto";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    33
        permission java.security.SecurityPermission "clearProviderProperties.OracleUcrypto";
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    34
        permission java.security.SecurityPermission "removeProviderProperty.OracleUcrypto";
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    35
        permission java.io.FilePermission "${java.home}/conf/security/ucrypto-solaris.cfg", "read";
27182
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    36
};
4525d13b8af1 8046002: Move Ucrypto to the open jdk repo
valeriep
parents: 25859
diff changeset
    37
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    38
grant codeBase "jrt:/jdk.crypto.ec" {
25408
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    39
        permission java.lang.RuntimePermission "accessClassInPackage.sun.security.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    40
        permission java.lang.RuntimePermission "loadLibrary.sunec";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    41
        permission java.util.PropertyPermission "*", "read";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    42
        permission java.security.SecurityPermission "putProviderProperty.SunEC";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    43
        permission java.security.SecurityPermission "clearProviderProperties.SunEC";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    44
        permission java.security.SecurityPermission "removeProviderProperty.SunEC";
24364
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    45
};
da8afb112f5d 8040059: Change default policy for extensions to no permission
mchung
parents: 22339
diff changeset
    46
27565
729f9700483a 8049367: Modular Run-Time Images
chegar
parents: 27182
diff changeset
    47
grant codeBase "jrt:/jdk.crypto.pkcs11" {
25408
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    48
        permission java.lang.RuntimePermission "accessClassInPackage.sun.security.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    49
        permission java.lang.RuntimePermission "accessClassInPackage.sun.nio.ch";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    50
        permission java.lang.RuntimePermission "loadLibrary.j2pkcs11";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    51
        // needs "security.pkcs11.allowSingleThreadedModules"
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    52
        permission java.util.PropertyPermission "*", "read";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    53
        permission java.security.SecurityPermission "putProviderProperty.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    54
        permission java.security.SecurityPermission "clearProviderProperties.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    55
        permission java.security.SecurityPermission "removeProviderProperty.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    56
        permission java.security.SecurityPermission "getProperty.auth.login.defaultCallbackHandler";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    57
        permission java.security.SecurityPermission "authProvider.*";
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    58
        // Needed for reading PKCS11 config file and NSS library check
27563093d2d2 8043406: Change default policy for JCE providers to run with as few privileges as possible
valeriep
parents: 24364
diff changeset
    59
        permission java.io.FilePermission "<<ALL FILES>>", "read";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    60
};
90ce3da70b43 Initial load
duke
parents:
diff changeset
    61
28849
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    62
grant codeBase "jrt:/java.xml.ws" {
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    63
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.xml.internal.*";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    64
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.istack.internal";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    65
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.istack.internal.*";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    66
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.org.apache.xerces.internal.*";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    67
        permission java.lang.RuntimePermission "accessDeclaredMembers";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    68
        permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    69
        permission java.util.PropertyPermission "*", "read";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    70
};
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    71
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    72
grant codeBase "jrt:/java.xml.bind" {
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    73
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.xml.internal.*";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    74
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.istack.internal";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    75
        permission java.lang.RuntimePermission "accessClassInPackage.com.sun.istack.internal.*";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    76
        permission java.lang.RuntimePermission "accessDeclaredMembers";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    77
        permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    78
        permission java.util.PropertyPermission "*", "read";
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    79
};
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    80
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    81
grant codeBase "jrt:/java.activation" {
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    82
        permission java.security.AllPermission;
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    83
};
ccf9d86e52ec 8057645: Deprivilege JAX-WS, JAXB, JAF to extension class loader
mchung
parents: 27565
diff changeset
    84
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    85
// default permissions granted to all domains
90ce3da70b43 Initial load
duke
parents:
diff changeset
    86
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    87
grant {
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    88
        // Allows any thread to stop itself using the java.lang.Thread.stop()
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    89
        // method that takes no argument.
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    90
        // Note that this permission is granted by default only to remain
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    91
        // backwards compatible.
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    92
        // It is strongly recommended that you either remove this permission
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    93
        // from this policy file or further restrict it to code sources
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    94
        // that you specify, because Thread.stop() is potentially unsafe.
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    95
        // See the API specification of java.lang.Thread.stop() for more
2183
8eb97a6368b8 6787130: java.policy file contains stale link to http://java.sun.com/notes
mullan
parents: 2
diff changeset
    96
        // information.
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    97
        permission java.lang.RuntimePermission "stopThread";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
    98
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
    99
        // allows anyone to listen on dynamic ports
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   100
        permission java.net.SocketPermission "localhost:0", "listen";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   101
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   102
        // "standard" properies that can be read by anyone
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   103
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   104
        permission java.util.PropertyPermission "java.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   105
        permission java.util.PropertyPermission "java.vendor", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   106
        permission java.util.PropertyPermission "java.vendor.url", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   107
        permission java.util.PropertyPermission "java.class.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   108
        permission java.util.PropertyPermission "os.name", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   109
        permission java.util.PropertyPermission "os.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   110
        permission java.util.PropertyPermission "os.arch", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   111
        permission java.util.PropertyPermission "file.separator", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   112
        permission java.util.PropertyPermission "path.separator", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   113
        permission java.util.PropertyPermission "line.separator", "read";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   114
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   115
        permission java.util.PropertyPermission "java.specification.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   116
        permission java.util.PropertyPermission "java.specification.vendor", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   117
        permission java.util.PropertyPermission "java.specification.name", "read";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   118
22339
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   119
        permission java.util.PropertyPermission "java.vm.specification.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   120
        permission java.util.PropertyPermission "java.vm.specification.vendor", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   121
        permission java.util.PropertyPermission "java.vm.specification.name", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   122
        permission java.util.PropertyPermission "java.vm.version", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   123
        permission java.util.PropertyPermission "java.vm.vendor", "read";
e91bfaf4360d 8011786: Better applet networking
michaelm
parents: 2183
diff changeset
   124
        permission java.util.PropertyPermission "java.vm.name", "read";
2
90ce3da70b43 Initial load
duke
parents:
diff changeset
   125
};
90ce3da70b43 Initial load
duke
parents:
diff changeset
   126