RFC: Make gij -Djava.security.manager work

Gary Benson gbenson@redhat.com
Fri Aug 4 09:08:00 GMT 2006


Hi all,

The attached patch makes gij -Djava.security.manager work, fixing
PR 28340.  It is designed to be applied after the SecurityManager
merge patch I mailed previously: I can't imagine anything working
without the proper AccessController stuff.

Comments?

Cheers,
Gary
-------------- next part --------------
Index: ChangeLog
===================================================================
--- ChangeLog	(revision 115901)
+++ ChangeLog	(working copy)
@@ -1,3 +1,17 @@
+2006-08-03  Gary Benson  <gbenson@redhat.com>
+
+	PR libgcj/28340:
+	* java/lang/ClassLoader.java (clinit): Install a default
+	security manager if java.security.manager is defined.
+	(getParent, getSystemClassLoader): Use the correct stack
+	frame during security checks.
+	* java/net/URLClassLoader.java (findClass): Avoid calling
+	this.toString() during VM initialization.
+	(runtimeInitialized): New method.
+	* java/net/natURLClassLoader.cc: New file.
+	* Makefile.am (nat_source_files): Added the above.
+	* Makefile.in: Rebuilt.
+
 2006-08-03  Gary Benson  <gbenson@redhat.com>
 	    Casey Marshall <csm@gnu.org>
 
Index: java/lang/ClassLoader.java
===================================================================
--- java/lang/ClassLoader.java	(revision 115901)
+++ java/lang/ClassLoader.java	(working copy)
@@ -38,6 +38,7 @@
 
 package java.lang;
 
+import gnu.classpath.SystemProperties;
 import gnu.java.util.DoubleEnumeration;
 import gnu.java.util.EmptyEnumeration;
 
@@ -156,6 +157,39 @@
   static final ClassLoader systemClassLoader =
     VMClassLoader.getSystemClassLoader();
 
+  static
+  {
+    // Find out if we have to install a default security manager. Note
+    // that this is done here because we potentially need the system
+    // class loader to load the security manager and note also that we
+    // don't need the security manager until the system class loader
+    // is created.  If the runtime chooses to use a class loader that
+    // doesn't have the system class loader as its parent, it is
+    // responsible for setting up a security manager before doing so.
+    String secman = SystemProperties.getProperty("java.security.manager");
+    if (secman != null && SecurityManager.current == null)
+    {
+      if (secman.equals("") || secman.equals("default"))
+      {
+	SecurityManager.current = new SecurityManager();
+      }
+      else
+      {
+	try
+	{
+	  Class cl = Class.forName(secman, false, systemClassLoader);
+	  SecurityManager.current = (SecurityManager) cl.newInstance();
+	}
+	catch (Exception x)
+	{
+	  throw (InternalError)
+	    new InternalError("Unable to create SecurityManager")
+	        .initCause(x);
+	}
+      }
+    }
+  }
+
   /**
    * The default protection domain, used when defining a class with a null
    * paramter for the domain.
@@ -496,7 +530,7 @@
     SecurityManager sm = System.getSecurityManager();
     if (sm != null)
       {
-        Class c = VMSecurityManager.getClassContext(ClassLoader.class)[1];
+        Class c = VMSecurityManager.getClassContext(ClassLoader.class)[0];
         ClassLoader cl = c.getClassLoader();
 	if (cl != null && ! cl.isAncestorOf(this))
           sm.checkPermission(new RuntimePermission("getClassLoader"));
@@ -739,7 +773,7 @@
     SecurityManager sm = System.getSecurityManager();
     if (sm != null)
       {
-	Class c = VMSecurityManager.getClassContext(ClassLoader.class)[1];
+	Class c = VMSecurityManager.getClassContext(ClassLoader.class)[0];
 	ClassLoader cl = c.getClassLoader();
 	if (cl != null && cl != systemClassLoader)
 	  sm.checkPermission(new RuntimePermission("getClassLoader"));
Index: java/net/URLClassLoader.java
===================================================================
--- java/net/URLClassLoader.java	(revision 115901)
+++ java/net/URLClassLoader.java	(working copy)
@@ -1078,7 +1078,12 @@
 	resource = loader.getResource(resourceName);
       }
     if (resource == null)
-      throw new ClassNotFoundException(className + " not found in " + this);
+      {
+	String message = className + " not found";
+	if (runtimeInitialized())
+	  message += " in " + this;
+	throw new ClassNotFoundException(message);
+      }
 
     // Try to read the class data, create the CodeSource, Package and
     // construct the class (and watch out for those nasty IOExceptions)
@@ -1437,4 +1442,11 @@
         return loader;
       }
   }
+
+  /**
+   * Tell whether runtime initialization is complete.
+   *
+   * @return whether runtime initialization is complete.
+   */
+  private static native boolean runtimeInitialized();  
 }
Index: java/net/natURLClassLoader.cc
===================================================================
--- java/net/natURLClassLoader.cc	(revision 0)
+++ java/net/natURLClassLoader.cc	(revision 0)
@@ -0,0 +1,22 @@
+// natURLClassLoader.cc -- Native part of the URLClassLoader class.
+
+/* Copyright (C) 2006 Free Software Foundation, Inc.
+
+   This file is part of libgcj.
+
+This software is copyrighted work licensed under the terms of the
+Libgcj License.  Please consult the file "LIBGCJ_LICENSE" for
+details.  */
+
+#include <config.h>
+
+#include <gcj/cni.h>
+#include <jvm.h>
+
+#include <java/net/URLClassLoader.h>
+
+jboolean
+java::net::URLClassLoader::runtimeInitialized ()
+{
+  return gcj::runtimeInitialized;
+}
Index: Makefile.am
===================================================================
--- Makefile.am	(revision 115901)
+++ Makefile.am	(working copy)
@@ -822,6 +822,7 @@
 java/lang/reflect/natMethod.cc \
 java/net/natVMNetworkInterface.cc \
 java/net/natInetAddress.cc \
+java/net/natURLClassLoader.cc \
 java/nio/channels/natVMChannels.cc \
 java/nio/natDirectByteBufferImpl.cc \
 java/security/natVMAccessController.cc \
Index: Makefile.in
===================================================================
--- Makefile.in	(revision 115901)
+++ Makefile.in	(working copy)
@@ -286,6 +286,7 @@
 	java/lang/reflect/natConstructor.cc \
 	java/lang/reflect/natField.cc java/lang/reflect/natMethod.cc \
 	java/net/natVMNetworkInterface.cc java/net/natInetAddress.cc \
+	java/net/natURLClassLoader.cc \
 	java/nio/channels/natVMChannels.cc \
 	java/nio/natDirectByteBufferImpl.cc \
 	java/security/natVMAccessController.cc \
@@ -328,6 +329,7 @@
 	java/lang/reflect/natConstructor.lo \
 	java/lang/reflect/natField.lo java/lang/reflect/natMethod.lo \
 	java/net/natVMNetworkInterface.lo java/net/natInetAddress.lo \
+	java/net/natURLClassLoader.lo \
 	java/nio/channels/natVMChannels.lo \
 	java/nio/natDirectByteBufferImpl.lo \
 	java/security/natVMAccessController.lo \
@@ -7136,6 +7138,7 @@
 java/lang/reflect/natMethod.cc \
 java/net/natVMNetworkInterface.cc \
 java/net/natInetAddress.cc \
+java/net/natURLClassLoader.cc \
 java/nio/channels/natVMChannels.cc \
 java/nio/natDirectByteBufferImpl.cc \
 java/security/natVMAccessController.cc \
@@ -7612,6 +7615,8 @@
 	java/net/$(DEPDIR)/$(am__dirstamp)
 java/net/natInetAddress.lo: java/net/$(am__dirstamp) \
 	java/net/$(DEPDIR)/$(am__dirstamp)
+java/net/natURLClassLoader.lo: java/net/$(am__dirstamp) \
+	java/net/$(DEPDIR)/$(am__dirstamp)
 java/nio/channels/$(am__dirstamp):
 	@$(mkdir_p) java/nio/channels
 	@: > java/nio/channels/$(am__dirstamp)
@@ -7931,6 +7936,8 @@
 	-rm -f java/lang/reflect/natMethod.lo
 	-rm -f java/net/natInetAddress.$(OBJEXT)
 	-rm -f java/net/natInetAddress.lo
+	-rm -f java/net/natURLClassLoader.$(OBJEXT)
+	-rm -f java/net/natURLClassLoader.lo
 	-rm -f java/net/natVMNetworkInterface.$(OBJEXT)
 	-rm -f java/net/natVMNetworkInterface.lo
 	-rm -f java/nio/channels/natVMChannels.$(OBJEXT)
@@ -8052,6 +8059,7 @@
 @AMDEP_TRUE@@am__include@ @am__quote@java/lang/reflect/$(DEPDIR)/natField.Plo@am__quote@
 @AMDEP_TRUE@@am__include@ @am__quote@java/lang/reflect/$(DEPDIR)/natMethod.Plo@am__quote@
 @AMDEP_TRUE@@am__include@ @am__quote@java/net/$(DEPDIR)/natInetAddress.Plo@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@java/net/$(DEPDIR)/natURLClassLoader.Plo@am__quote@
 @AMDEP_TRUE@@am__include@ @am__quote@java/net/$(DEPDIR)/natVMNetworkInterface.Plo@am__quote@
 @AMDEP_TRUE@@am__include@ @am__quote@java/nio/$(DEPDIR)/natDirectByteBufferImpl.Plo@am__quote@
 @AMDEP_TRUE@@am__include@ @am__quote@java/nio/channels/$(DEPDIR)/natVMChannels.Plo@am__quote@


More information about the Java-patches mailing list