# Cannot give custom plugin permission org.elasticsearch.secure\_sm.ThreadPermission "modifyArbitraryThreadGroup"

**URL:** <https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720>\
**Category:** Elasticsearch\
**Created:** [December 7, 2022, 8:40pm UTC](https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720 "2022-12-07T20:40:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![smillies](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smillies/32/114371_2.png) [@smillies](https://discuss.elastic.co/u/smillies)\
**Post date:** [December 7, 2022, 8:40pm UTC](https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720/1 "2022-12-07T20:40:26Z")

</div>

I have written a custom plugin that includes some third-party jars that do magic stuff requiring certain permissions. So I have added them to my plugin-security.policy like this

```auto
grant {
  permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
  permission org.elasticsearch.secure_sm.ThreadPermission "modifyArbitraryThreadGroup";
};

```

I'm also doing all sensitive stuff inside `AccessController.doPrivileged` and that's fine while only dealing with reflection. However, after adding the thread permission, ES does not even start up. (I'm trying to run it under gradle and the run task fails.)

I have a suspicion what might the cause: There is an `org.elasticsearch.bootstrap.PolicyUtil`, see [here](https://github.com/elastic/elasticsearch/blob/8.5/server/src/main/java/org/elasticsearch/bootstrap/PolicyUtil.java). In line 177 it sets the ALLOWED\_PLUGIN\_PERMISSIONS. If you look at the elements that are put into this collection, they are quite limited.

Does this mean that I cannot give my plugin jars all the permissions I want them to have? In particular, not the one mentioned above? Or is there a way around this? Can I somehow wrap this policy in my own and pre-empt the validation that is apparently done in method `getModulePolicyInfo`?

Perhaps I'm way off track here? This is the first time I have to do with a custom plugin, and documentation on plugin security is a bit scarce.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2023, 8:41pm UTC](https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720/2 "2023-01-04T20:41:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
