You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@lucene.apache.org by "Uwe Schindler (Jira)" <ji...@apache.org> on 2020/09/09 17:52:00 UTC
[jira] [Comment Edited] (LUCENE-9517) BugfixDeflater_JDK8252739
causes Java security issues in JDK 11
[ https://issues.apache.org/jira/browse/LUCENE-9517?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17193073#comment-17193073 ]
Uwe Schindler edited comment on LUCENE-9517 at 9/9/20, 5:51 PM:
----------------------------------------------------------------
Here is a PR not trying to subclass Deflater, which was causing this bug: https://github.com/apache/lucene-solr/pull/1850
The idea is to just provide a patch for the setDictionary method, provided by a functional interface. In non-buggy JVMs it points dircetly to the corresponding Deflater method, otherwise it provides the workaround using the arraycopy and a scratchBuffer.
This also allowed to put setDictionary on the forbiddenapis list.
was (Author: thetaphi):
Here is a PR not trying to subclass Deflater, whcih was causing this bug: https://github.com/apache/lucene-solr/pull/1850
The idea is to ust provide a patch for the setDictionary method, provided by a functional interface. In non-buggy JVMs it points dircetly to the corresponding Deflater method, otherwise it provides the workaround using the arraycopy and a scratchBuffer.
This also allowed to put setDictionary on the forbiddenapis list.
> BugfixDeflater_JDK8252739 causes Java security issues in JDK 11
> ---------------------------------------------------------------
>
> Key: LUCENE-9517
> URL: https://issues.apache.org/jira/browse/LUCENE-9517
> Project: Lucene - Core
> Issue Type: Bug
> Components: core/index
> Affects Versions: 8.x, master (9.0)
> Reporter: Ignacio Vera
> Assignee: Uwe Schindler
> Priority: Major
> Labels: Java10, Java11
> Fix For: 8.x, master (9.0)
>
> Time Spent: 3h 10m
> Remaining Estimate: 0h
>
> We are running into issues when running Elasticsearch CI with java security turned on and using JDK11 (only for the ones that contains the jdk bug ). The errors look like:
>
>
> {code:java}
> java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "accessDeclaredMembers") {code}
>
> The issue seems to be here:
> [http://hg.openjdk.java.net/jdk/jdk11/file/1ddf9a99e4ad/src/java.base/share/classes/java/util/zip/Deflater.java#l989]
> As we now have a subclass that wants to run this code. Note that this code has been removed in JDK12 and above.
> We might need to wrap the creation of this object in a doPriviledged Block or find a different solution that does not need to subclass the Deflater class.
>
> cc: [~uschindler]
>
>
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@lucene.apache.org
For additional commands, e-mail: issues-help@lucene.apache.org