Blame SOURCES/rh1883849-cryptoki_access_to_sunjce_with_security_manager.patch

3fa52e
# HG changeset patch
3fa52e
# User Zdenek Zambersky <zzambers@redhat.com>
3fa52e
# Date 1601403587 -7200
3fa52e
#      Tue Sep 29 20:19:47 2020 +0200
3fa52e
# Node ID f77ac813eee61b2e9616b2d71a2c5372d0cbd158
3fa52e
# Parent  d484fdfcc7d5c21812de8a0712236d077b0f2dde
3fa52e
Fixed default policy for jdk.crypto.cryptoki
3fa52e
3fa52e
diff -r d484fdfcc7d5 -r f77ac813eee6 src/java.base/share/lib/security/default.policy
3fa52e
--- openjdk.orig/src/java.base/share/lib/security/default.policy	Wed Sep 02 07:36:15 2020 +0200
3fa52e
+++ openjdk/src/java.base/share/lib/security/default.policy	Tue Sep 29 20:19:47 2020 +0200
3fa52e
@@ -124,6 +124,8 @@
3fa52e
 grant codeBase "jrt:/jdk.crypto.cryptoki" {
3fa52e
     permission java.lang.RuntimePermission
3fa52e
                    "accessClassInPackage.sun.security.*";
3fa52e
+    permission java.lang.RuntimePermission
3fa52e
+                   "accessClassInPackage.com.sun.crypto.provider";
3fa52e
     permission java.lang.RuntimePermission "accessClassInPackage.sun.nio.ch";
3fa52e
     permission java.lang.RuntimePermission "loadLibrary.j2pkcs11";
3fa52e
     permission java.util.PropertyPermission "sun.security.pkcs11.allowSingleThreadedModules", "read";
3fa52e
# HG changeset patch
3fa52e
# User Zdenek Zambersky <zzambers@redhat.com>
3fa52e
# Date 1601419086 -7200
3fa52e
#      Wed Sep 30 00:38:06 2020 +0200
3fa52e
# Node ID 02c8b154f728be3dd06239a98519d654e2127186
3fa52e
# Parent  f77ac813eee61b2e9616b2d71a2c5372d0cbd158
3fa52e
P11Util: Create provider in priviledged block
3fa52e
3fa52e
diff -r f77ac813eee6 -r 02c8b154f728 src/jdk.crypto.cryptoki/share/classes/sun/security/pkcs11/P11Util.java
3fa52e
--- openjdk.orig/src/jdk.crypto.cryptoki/share/classes/sun/security/pkcs11/P11Util.java	Tue Sep 29 20:19:47 2020 +0200
3fa52e
+++ openjdk/src/jdk.crypto.cryptoki/share/classes/sun/security/pkcs11/P11Util.java	Wed Sep 30 00:38:06 2020 +0200
3fa52e
@@ -87,14 +87,20 @@
3fa52e
         }
3fa52e
         p = Security.getProvider(providerName);
3fa52e
         if (p == null) {
3fa52e
-            try {
3fa52e
-                @SuppressWarnings("deprecation")
3fa52e
-                Object o = Class.forName(className).newInstance();
3fa52e
-                p = (Provider)o;
3fa52e
-            } catch (Exception e) {
3fa52e
-                throw new ProviderException
3fa52e
-                        ("Could not find provider " + providerName, e);
3fa52e
-            }
3fa52e
+            p = AccessController.doPrivileged(
3fa52e
+                new PrivilegedAction<Provider>() {
3fa52e
+                    public Provider run() {
3fa52e
+                        try {
3fa52e
+                            @SuppressWarnings("deprecation")
3fa52e
+                            Object o = Class.forName(className).newInstance();
3fa52e
+                            return (Provider) o;
3fa52e
+                        } catch (Exception e) {
3fa52e
+                            throw new ProviderException
3fa52e
+                                ("Could not find provider " + providerName, e);
3fa52e
+                        }
3fa52e
+                    }
3fa52e
+                }
3fa52e
+            );
3fa52e
         }
3fa52e
         return p;
3fa52e
     }