# Previously working groovy script fails

**URL:** <https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110>\
**Category:** Elasticsearch\
**Created:** [July 9, 2016, 1:00pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110 "2016-07-09T13:00:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 9, 2016, 1:00pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/1 "2016-07-09T13:00:58Z")

</div>

Running ES 2.3.3 on openjdk 8u92 with the following policy file (with -Djava.security.policy=java.policy):  
grant {  
permission org.elasticsearch.script.ClassPermission "\*";  
};

produces this exception while I try to execute the script:  
"caused\_by":{"type":"script\_exception","reason":"failed to run file script [report] using lang [groovy]","caused\_by":{"type":"security\_exception","reason":"access denied (\"java.lang.Runtime Permission\" \"accessClassInPackage.sun.misc\")"}}},"status":400}"

This has worked before, but I can't remember whether the openjdk or the ES upgrade made it fail.  
Any ideas where should I look? The scripts are stored on local disk, remote scripting is disabled, so I would like to grant all permissions to them.

---

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 9, 2016, 2:07pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/2 "2016-07-09T14:07:03Z")

</div>

After downgrading to 8u77, everything works fine again. Can I work this around somehow?

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [July 9, 2016, 4:46pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/3 "2016-07-09T16:46:58Z")

</div>

So, OpenJDK 8u77, but still Elasticsearch 2.3.3, and your script execution works?

---

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 9, 2016, 4:47pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/4 "2016-07-09T16:47:47Z")

</div>

Yes. Everything else is the same (I hope).

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [July 9, 2016, 5:37pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/5 "2016-07-09T17:37:10Z")

</div>

This is a Groovy thing. The mentioned package "sun.misc" is a Java internal API and, hence, subject to any manner of changes even in minor releases, and, unfortunately, Groovy depends on some of those, which, as you can see, it shouldn't.

Issues like this are among the reasons that developers have come up with a new scripting language, "Painless", that will be part of the ESv5.0 release.

In the meantime, maybe you could post your script here in the hopes that someone can identify the part that provokes this issue and suggest an alternative. (e.g. if you are using a closure, you could use a loop instead.)

---

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 9, 2016, 5:52pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/6 "2016-07-09T17:52:51Z")

</div>

Is there a way to add a permission for this?  
I've already tried:  
grant {  
permission org.elasticsearch.script.ClassPermission "\*";  
permission java.lang.RuntimePermission "accessClassInPackage.sun.misc";  
};  
without success.

---

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 12, 2016, 7:44am UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/7 "2016-07-12T07:44:36Z")

</div>

Any idea about how this should be enabled?

Thanks,

---

<div class="post-metadata">

**Author:** ![Attila\_Nagy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attila_nagy/32/46906_2.png) [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Post date:** [July 18, 2016, 12:32pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/8 "2016-07-18T12:32:47Z")

</div>

`def deepcopy(orig) { bos = new ByteArrayOutputStream() oos = new ObjectOutputStream(bos) oos.writeObject(orig); oos.flush() bin = new ByteArrayInputStream(bos.toByteArray()) ois = new ObjectInputStream(bin) return ois.readObject() }`

This is what I try to use and what fails.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:34pm UTC](https://discuss.elastic.co/t/previously-working-groovy-script-fails/55110/9 "2017-07-05T22:34:43Z")

</div>


