Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id F0E0A200BA5 for ; Wed, 5 Oct 2016 02:17:23 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id EF832160ADC; Wed, 5 Oct 2016 00:17:23 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 390B3160ACC for ; Wed, 5 Oct 2016 02:17:23 +0200 (CEST) Received: (qmail 97318 invoked by uid 500); 5 Oct 2016 00:17:22 -0000 Mailing-List: contact issues-help@geode.incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@geode.incubator.apache.org Delivered-To: mailing list issues@geode.incubator.apache.org Received: (qmail 97309 invoked by uid 99); 5 Oct 2016 00:17:22 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd4-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 05 Oct 2016 00:17:22 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd4-us-west.apache.org (ASF Mail Server at spamd4-us-west.apache.org) with ESMTP id 09D99C1362 for ; Wed, 5 Oct 2016 00:17:22 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd4-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: -6.219 X-Spam-Level: X-Spam-Status: No, score=-6.219 tagged_above=-999 required=6.31 tests=[KAM_ASCII_DIVIDERS=0.8, KAM_LAZY_DOMAIN_SECURITY=1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-2.999] autolearn=disabled Received: from mx2-lw-us.apache.org ([10.40.0.8]) by localhost (spamd4-us-west.apache.org [10.40.0.11]) (amavisd-new, port 10024) with ESMTP id GVPsPlmRMWD7 for ; Wed, 5 Oct 2016 00:17:21 +0000 (UTC) Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx2-lw-us.apache.org (ASF Mail Server at mx2-lw-us.apache.org) with SMTP id 0A1A25F399 for ; Wed, 5 Oct 2016 00:17:20 +0000 (UTC) Received: (qmail 96785 invoked by uid 99); 5 Oct 2016 00:17:20 -0000 Received: from arcas.apache.org (HELO arcas) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 05 Oct 2016 00:17:20 +0000 Received: from arcas.apache.org (localhost [127.0.0.1]) by arcas (Postfix) with ESMTP id 7D9902C0B05 for ; Wed, 5 Oct 2016 00:17:20 +0000 (UTC) Date: Wed, 5 Oct 2016 00:17:20 +0000 (UTC) From: "Diane Hardman (JIRA)" To: issues@geode.incubator.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (GEODE-1960) Provide protection against malicious developer jars deployed as functions MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 archived-at: Wed, 05 Oct 2016 00:17:24 -0000 [ https://issues.apache.org/jira/browse/GEODE-1960?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15547149#comment-15547149 ] Diane Hardman commented on GEODE-1960: -------------------------------------- Yes, the administrator deploys the function but may not be the appropriate person to review the code in the function. It would be nice if we could protect ourselves from potentially malicious code in a function. > Provide protection against malicious developer jars deployed as functions > ------------------------------------------------------------------------- > > Key: GEODE-1960 > URL: https://issues.apache.org/jira/browse/GEODE-1960 > Project: Geode > Issue Type: Improvement > Components: functions, security > Reporter: Diane Hardman > Priority: Minor > > Provide protection for functions that might contain malicious calls like System.exit(). -- This message was sent by Atlassian JIRA (v6.3.4#6332)