test/script/sandbox/NASHORN-525.js

Fri, 21 Dec 2012 16:36:24 -0400

author
jlaskey
date
Fri, 21 Dec 2012 16:36:24 -0400
changeset 3
da1e581c933b
child 7
5a1b0714df0e
permissions
-rw-r--r--

8005403: Open-source Nashorn
Reviewed-by: attila, hannesw, lagergren, sundar
Contributed-by: james.laskey@oracle.com, akhil.arora@oracle.com, andreas.woess@jku.at, attila.szegedi@oracle.com, hannes.wallnoefer@oracle.com, henry.jen@oracle.com, marcus.lagergren@oracle.com, pavel.semenov@oracle.com, pavel.stepanov@oracle.com, petr.hejl@oracle.com, petr.pisl@oracle.com, sundararajan.athijegannathan@oracle.com

     1 /*
     2  * Copyright (c) 2010, 2012, Oracle and/or its affiliates. All rights reserved.
     3  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
     4  * 
     5  * This code is free software; you can redistribute it and/or modify it
     6  * under the terms of the GNU General Public License version 2 only, as
     7  * published by the Free Software Foundation.
     8  * 
     9  * This code is distributed in the hope that it will be useful, but WITHOUT
    10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
    11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
    12  * version 2 for more details (a copy is included in the LICENSE file that
    13  * accompanied this code).
    14  * 
    15  * You should have received a copy of the GNU General Public License version
    16  * 2 along with this work; if not, write to the Free Software Foundation,
    17  * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
    18  * 
    19  * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
    20  * or visit www.oracle.com if you need additional information or have any
    21  * questions.
    22  */
    24 /**
    25  * NASHORN-525 : nashorn misses security access checks 
    26  *
    27  * @test
    28  * @run
    29  */
    31 function check(code) {
    32     try {
    33         eval(code);
    34         fail("SecurityException expected for : " + code);
    35     } catch (e) {
    36         if (! (e instanceof java.lang.SecurityException)) {
    37             fail("SecurityException expected, but got " + e);
    38         }
    39     }
    40 }
    42 // if security manager is absent, pass the test vacuously.
    43 if (java.lang.System.getSecurityManager() != null) {
    44     // try accessing class from 'sun.*' packages
    45     check("Packages.sun.misc.Unsafe");
    46     check("Java.type('sun.misc.Unsafe')");
    48     // TODO this works in Java8 but not in Java8, disabling for now
    49     check("java.lang.Class.forName('sun.misc.Unsafe')");
    51     // try System.exit and System.loadLibrary
    52     check("java.lang.System.exit(0)");
    53     check("java.lang.System.loadLibrary('foo')");
    54 }

mercurial