Path: blob/master/src/jdk.dynalink/share/classes/jdk/dynalink/beans/CheckRestrictedPackage.java
41161 views
/*1* Copyright (c) 2010, 2021, Oracle and/or its affiliates. All rights reserved.2* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.3*4* This code is free software; you can redistribute it and/or modify it5* under the terms of the GNU General Public License version 2 only, as6* published by the Free Software Foundation. Oracle designates this7* particular file as subject to the "Classpath" exception as provided8* by Oracle in the LICENSE file that accompanied this code.9*10* This code is distributed in the hope that it will be useful, but WITHOUT11* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or12* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License13* version 2 for more details (a copy is included in the LICENSE file that14* accompanied this code).15*16* You should have received a copy of the GNU General Public License version17* 2 along with this work; if not, write to the Free Software Foundation,18* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.19*20* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA21* or visit www.oracle.com if you need additional information or have any22* questions.23*/2425/*26* This file is available under and governed by the GNU General Public27* License version 2 only, as published by the Free Software Foundation.28* However, the following notice accompanied the original version of this29* file, and Oracle licenses the original version of this file under the BSD30* license:31*/32/*33Copyright 2009-2013 Attila Szegedi3435Redistribution and use in source and binary forms, with or without36modification, are permitted provided that the following conditions are37met:38* Redistributions of source code must retain the above copyright39notice, this list of conditions and the following disclaimer.40* Redistributions in binary form must reproduce the above copyright41notice, this list of conditions and the following disclaimer in the42documentation and/or other materials provided with the distribution.43* Neither the name of the copyright holder nor the names of44contributors may be used to endorse or promote products derived from45this software without specific prior written permission.4647THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS48IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED49TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A50PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL COPYRIGHT HOLDER51BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR52CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF53SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR54BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,55WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR56OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF57ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.58*/5960package jdk.dynalink.beans;6162import java.lang.reflect.Modifier;63import java.security.AccessControlContext;64import java.security.AccessController;65import java.security.PrivilegedAction;66import jdk.dynalink.internal.AccessControlContextFactory;6768/**69* A utility class to check whether a given class is in a package with restricted access e.g. "sun.*" etc.70*/71class CheckRestrictedPackage {72@SuppressWarnings("removal")73private static final AccessControlContext NO_PERMISSIONS_CONTEXT =74AccessControlContextFactory.createAccessControlContext();7576/**77* Returns true if the class is either not public, or it resides in a package with restricted access.78* @param clazz the class to test79* @return true if the class is either not public, or it resides in a package with restricted access.80*/81@SuppressWarnings("removal")82static boolean isRestrictedClass(final Class<?> clazz) {83if(!Modifier.isPublic(clazz.getModifiers())) {84// Non-public classes are always restricted85return true;86}87final String name = clazz.getName();88final int i = name.lastIndexOf('.');89if (i == -1) {90// Classes in default package are never restricted91return false;92}93final String pkgName = name.substring(0, i);94final Module module = clazz.getModule();95if (module != null && !module.isExported(pkgName)) {96// Classes in unexported packages of modules are always restricted97return true;98}99100final SecurityManager sm = System.getSecurityManager();101if(sm == null) {102// No further restrictions if we don't have a security manager103return false;104}105// Do a package access check from within an access control context with no permissions106try {107AccessController.doPrivileged((PrivilegedAction<Void>) () -> {108sm.checkPackageAccess(pkgName);109return null;110}, NO_PERMISSIONS_CONTEXT);111} catch(final SecurityException e) {112return true;113}114return false;115}116}117118119