dweiss commented on PR #13146:
URL: https://github.com/apache/lucene/pull/13146#issuecomment-1977211889
Ok, I forgot we actually allow gradle to do anything:
```
// Grant all permissions to Gradle test runner classes.
grant codeBase "file:${gradle.lib.dir}${/}-" {
permission java.security.AllPermission;
};
grant codeBase "file:${gradle.worker.jar}" {
permission java.security.AllPermission;
};
```
I think I could try to locate places in RandomizedRunner where it calls into
JUnit without doPrivileged... not sure if it's worth the hassle though - maybe
adding permissions for just those three jars is fine (we can compute the URLs
and pass them as properties)?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]