lucene-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Robert Muir (Jira)" <>
Subject [jira] [Commented] (SOLR-13986) remove "execute" permission from solr-tests.policy
Date Sun, 01 Dec 2019 02:43:00 GMT


Robert Muir commented on SOLR-13986:

I implemented patch with my workaround from before.

Note that 2 tests still fail: HdfsThreadLeakTest, TestHdfsCloudBackupRestore

The problem is hadoop test code (MiniDFSCluster.createPermissionsDiagnosisString):

It calls File.canExecute, but doesn't handle SecurityException. This is clearly documented
in the api:

I think I can hack around it but someone should really do something about this hadoop code.

> remove "execute" permission from solr-tests.policy
> --------------------------------------------------
>                 Key: SOLR-13986
>                 URL:
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Robert Muir
>            Priority: Major
>         Attachments: SOLR-13986-notyet.patch, SOLR-13986.patch
> If we don't really need to execute processes, we can take the permission away. That way
any attempt to execute something results in a SecurityException rather than running a process.
> It is necessary to first fix the tests policy before thinking about supporting securitymanager
in solr. This way we can ensure functionality does not break via our tests.

This message was sent by Atlassian Jira

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message