java.lang

Class RuntimePermission

Implemented Interfaces:
Guard, Serializable

public final class RuntimePermission
extends BasicPermission

A RuntimePermission contains a permission name, but no actions list. This means you either have the permission or you don't. Permission names have the follow the hierarchial property naming convention. In addition, an asterisk may appear at the end of a name if following a period or by itself.
Valid namesInvalid names
"accessClassInPackage.*","*" "**", "*x", "*.a"

The following table provides a list of all the possible RuntimePermission permission names with a description of what that permission allows.
Permission NamePermission AllowsRisks
createClassLoader creation of a class loader a class loader can load rogue classes which bypass all security permissions
getClassLoader retrieval of the class loader for the calling class rogue code could load classes not otherwise available
setContextClassLoader allows the setting of the context class loader used by a thread rogue code could change the context class loader needed by system threads
setSecurityManager allows the application to replace the security manager the new manager may be less restrictive, so that rogue code can bypass existing security checks
createSecurityManager allows the application to create a new security manager rogue code can use the new security manager to discover information about the execution stack
exitVM allows the application to halt the virtual machine rogue code can mount a denial-of-service attack by killing the virtual machine
shutdownHooks allows registration and modification of shutdown hooks rogue code can add a hook that interferes with clean virtual machine shutdown
setFactory allows the application to set the socket factory for socket, server socket, stream handler, or RMI socket factory. rogue code can create a rogue network object which mangles or intercepts data
setIO allows the application to set System.out, System.in, and System.err rogue code could sniff user input and intercept or mangle output
modifyThread allows the application to modify any thread in the virtual machine using any of the methods stop, resume, suspend, setPriority, and setName of classs Thread rogue code could adversely modify system or user threads
stopThread allows the application to stop any thread it has access to in the system rogue code can stop arbitrary threads
modifyThreadGroup allows the application to modify thread groups using any of the methods destroy, resume, setDaemon, setMaxPriority, stop, and suspend of the class ThreadGroup rogue code can mount a denial-of-service attack by changing run priorities
getProtectionDomain retrieve a class's ProtectionDomain rogue code can gain information about the security policy, to prepare a better attack
readFileDescriptor read a file descriptor rogue code can read sensitive information
writeFileDescriptor write a file descriptor rogue code can write files, including viruses, and can modify the virtual machine binary; if not just fill up the disk
loadLibrary.library name dynamic linking of the named library native code can bypass many security checks of pure Java
accessClassInPackage.package name access to a package via a ClassLoader rogue code can access classes not normally available
defineClassInPackage.package name define a class inside a given package rogue code can install rogue classes, including in trusted packages like java.security or java.lang
accessDeclaredMembers access declared class members via reflection rogue code can discover information, invoke methods, or modify fields that are not otherwise available
queuePrintJob initiate a print job rogue code could make a hard copy of sensitive information, or simply waste paper

Since:
1.2

See Also:
BasicPermission, Permission, SecurityManager, Serialized Form

Constructor Summary

RuntimePermission(String permissionName)
Create a new permission with the specified name.
RuntimePermission(String permissionName, String actions)
Create a new permission with the specified name.

Method Summary

Methods inherited from class java.security.BasicPermission

equals, getActions, hashCode, implies, newPermissionCollection

Methods inherited from class java.security.Permission

checkGuard, equals, getActions, getName, hashCode, implies, newPermissionCollection, toString

Methods inherited from class java.lang.Object

clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait

Constructor Details

RuntimePermission

public RuntimePermission(String permissionName)
Create a new permission with the specified name.

Parameters:
permissionName - the name of the granted permission

Throws:
NullPointerException - if name is null
IllegalArgumentException - thrown if name is empty or invalid


RuntimePermission

public RuntimePermission(String permissionName,
                         String actions)
Create a new permission with the specified name. The actions argument is ignored, as runtime permissions have no actions.

Parameters:
permissionName - the name of the granted permission
actions - ignored

Throws:
NullPointerException - if name is null
IllegalArgumentException - thrown if name is empty or invalid


RuntimePermission.java -- permission for a secure runtime action Copyright (C) 1998, 2000, 2002, 2005 Free Software Foundation, Inc. This file is part of GNU Classpath. GNU Classpath is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2, or (at your option) any later version. GNU Classpath is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with GNU Classpath; see the file COPYING. If not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. Linking this library statically or dynamically with other modules is making a combined work based on this library. Thus, the terms and conditions of the GNU General Public License cover the whole combination. As a special exception, the copyright holders of this library give you permission to link this library with independent modules to produce an executable, regardless of the license terms of these independent modules, and to copy and distribute the resulting executable under terms of your choice, provided that you also meet, for each linked independent module, the terms and conditions of the license of that module. An independent module is a module which is not derived from or based on this library. If you modify this library, you may extend this exception to your version of the library, but you are not obligated to do so. If you do not wish to do so, delete this exception statement from your version.