# Plugin-security.policy has not effect

**URL:** <https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405>\
**Category:** Elasticsearch\
**Created:** [January 23, 2019, 12:36pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405 "2019-01-23T12:36:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ninesalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninesalt/32/39981_2.png) [@ninesalt](https://discuss.elastic.co/u/ninesalt)\
**Post date:** [January 23, 2019, 12:36pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/1 "2019-01-23T12:36:33Z")

</div>

I'm trying to build a plugin that needs the following permissions:

```
grant {
  permission java.lang.RuntimePermission "accessDeclaredMembers";
};

```

When I install the plugin I get the warning saying that the plugin asks for permissions (which means the installation sees the above) but then when I try to use the plugin I get an error saying:

> java.security.AccessControlException: access denied ("java.lang.RuntimePermission" "accessDeclaredMembers")

What gives?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 23, 2019, 1:02pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/2 "2019-01-23T13:02:36Z")

</div>

Did you read this? [https://www.elastic.co/guide/en/elasticsearch/plugins/current/plugin-authors.html#plugin-authors-jsm](https://www.elastic.co/guide/en/elasticsearch/plugins/current/plugin-authors.html#plugin-authors-jsm)

---

<div class="post-metadata">

**Author:** ![ninesalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninesalt/32/39981_2.png) [@ninesalt](https://discuss.elastic.co/u/ninesalt)\
**Post date:** [January 23, 2019, 1:15pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/3 "2019-01-23T13:15:05Z")

</div>

Yes I have. I have my code in a `doPrivileged` block but it's not changing anything.

```
 public int analyzeSentiment(String text){
   return AccessController.doPrivileged(new PrivilegedAction<Integer>() {
        public Integer run(){
            StringByValue str = new StringByValue();
            str.setP(text);
            str.setN(text.length());
            return gs.ClassifySentiment(str);
        }
    });
}

```

PS: I think the ES docs for plugins (for authors) have to be a lot more expansive than they are. There is barely any documentation for it apart from the page you linked and the 4 examples linked in it.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 23, 2019, 2:52pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/4 "2019-01-23T14:52:26Z")

</div>

Are you sure the policy file is within the plugin distribution ? When you install it, are you prompted to authorize additional settings?

---

<div class="post-metadata">

**Author:** ![ninesalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninesalt/32/39981_2.png) [@ninesalt](https://discuss.elastic.co/u/ninesalt)\
**Post date:** [January 23, 2019, 2:56pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/5 "2019-01-23T14:56:22Z")

</div>

Yes. When it installs I get the big warning with all the `@` symbols. However I'm using docker so there's no stdin so I'm using the `-b` flag for the installation (don't think that makes a difference). Then I get a message saying `successfully installed *plugin_name*`. I also checked the actual build to make sure the file is there. I'm running out of ideas here.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 23, 2019, 4:08pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/6 "2019-01-23T16:08:47Z")

</div>

I don't know. May be @rjernst knows?

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [January 23, 2019, 8:24pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/7 "2019-01-23T20:24:50Z")

</div>

If the permission check is failing, something on the stack does not have permission. You can debug this using the security debug sysprop in java:  
[https://docs.oracle.com/javase/8/docs/technotes/guides/troubleshoot/envvars003.html](https://docs.oracle.com/javase/8/docs/technotes/guides/troubleshoot/envvars003.html)

Add this to your jvm.options:  
`-Djava.security.debug=access,failure`

Then find the failure and paste here (in a gist if it is large), it should show exactly what is failing the check.

---

<div class="post-metadata">

**Author:** ![ninesalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninesalt/32/39981_2.png) [@ninesalt](https://discuss.elastic.co/u/ninesalt)\
**Post date:** [January 23, 2019, 9:00pm UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/8 "2019-01-23T21:00:36Z")

</div>

Okay so I did that. [Here's](https://pastebin.com/0f9tJHpp) the paste of the relevant part of the debug log. I can't really figure out what's making it fail.

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [January 24, 2019, 2:01am UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/9 "2019-01-24T02:01:31Z")

</div>

The way to read this is to look at the failing stack, back to the doPrivileged call:

```auto
access: access denied ("java.lang.RuntimePermission" "accessDeclaredMembers")
java.lang.Exception: Stack trace
    at java.base/java.lang.Thread.dumpStack(Thread.java:1387)
    at java.base/java.security.AccessControlContext.checkPermission(AccessControlContext.java:462)
    at java.base/java.security.AccessController.checkPermission(AccessController.java:895)
    at java.base/java.lang.SecurityManager.checkPermission(SecurityManager.java:322)
    at java.base/java.lang.Class.checkMemberAccess(Class.java:2848)
    at java.base/java.lang.Class.getDeclaredFields(Class.java:2247)
    at com.sun.jna.Structure.getFieldList(Structure.java:931)
    at com.sun.jna.Structure.validateFields(Structure.java:1160)
    at com.sun.jna.Structure.<init>(Structure.java:189)
    at com.sun.jna.Structure.<init>(Structure.java:182)
    at com.sun.jna.Structure.<init>(Structure.java:169)
    at com.sun.jna.Structure.<init>(Structure.java:161)
    at de.spinscale.elasticsearch.ingest.sentiment.GoString.<init>(GoString.java:16)
    at de.spinscale.elasticsearch.ingest.sentiment.SentimentAnalyzer.lambda$analyzeSentiment$0(SentimentAnalyzer.java:41)
    at java.base/java.security.AccessController.doPrivileged(Native Method)

```

Everything on that stack must have permission. Later in the log, we see exactly what doesn't have permission:

```auto
access: domain that failed ProtectionDomain (file:/usr/share/elasticsearch/lib/jna-4.5.1.jar <no signer certificates>)

```

The problem is jna is a jar provided by elasticsearch, and your bare `grant` statement only applies to jars provided by your plugin. Unfortunately there isn't currently a way for a plugin to extend the permissions of core jars.

I see three possible solutions:

- Modify your code to not use jna
- Modify your jna usage to not trigger accessDeclaredMembers (note that this means you are getting all private/protected variables and methods, is this really necessary, or do you just need public?)
- Set the system policy to give jna access (elasticsearch builds on this policy if it exists). This will be tricky, as you need to give the exact path to the jna jar within the elasticsearch installation. It would look something like this:

```auto
grant codeBase "/usr/share/elasticsearch/lib/jna-4.5.1.jar" {
   permission java.lang.RuntimePermission "accessDeclaredMembers";
}

```

Note however that this is extremely fragile: it can and will change as elasticsearch in upgraded, so the first two options are much better, but this might get you by temporarily.

---

<div class="post-metadata">

**Author:** ![ninesalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninesalt/32/39981_2.png) [@ninesalt](https://discuss.elastic.co/u/ninesalt)\
**Post date:** [January 24, 2019, 11:18am UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/10 "2019-01-24T11:18:06Z")

</div>

Just tried option 3 and it doesn't work. The [debug log](https://pastebin.com/xfSrVqvU) is pretty much the same. Also I think it should be:

```
grant codeBase "file:/usr/share/elasticsearch/lib/jna-4.5.1.jar" {
   permission java.lang.RuntimePermission "accessDeclaredMembers";
} 

```

Without the `file:` prefix it gives me an error about a malformed URL and _with_ it, it seems like it doesn't recognize it because I'm not getting the warning when installing the plugin now.

Regarding the second option, I'm not explicitly calling any protected or private code myself. I'm just inheriting a class from JNA which apparently has some protected/private methods (including the constructor) so I can't even use it as a superclass. It sucks that this is so hard to do 😕

I'm not going to use JNA anymore. I found a decent alternative but I have to execute a binary. I changed the security permissions and I'm now getting a `nullpointerexception` because ES apparently doesn't have permission to execute the file (even though I gave it read and execute perms):

> exception: java.io.IOException: Cannot run program "/usr/share/elasticsearch/bin/ingest-opennlp/sentiment": error=13, Permission denied

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2019, 11:18am UTC](https://discuss.elastic.co/t/plugin-security-policy-has-not-effect/165405/11 "2019-02-21T11:18:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
