1 /*
   2  * Copyright (c) 2010, 2013, Oracle and/or its affiliates. All rights reserved.
   3  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
   4  *
   5  * This code is free software; you can redistribute it and/or modify it
   6  * under the terms of the GNU General Public License version 2 only, as
   7  * published by the Free Software Foundation.
   8  *
   9  * This code is distributed in the hope that it will be useful, but WITHOUT
  10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
  11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
  12  * version 2 for more details (a copy is included in the LICENSE file that
  13  * accompanied this code).
  14  *
  15  * You should have received a copy of the GNU General Public License version
  16  * 2 along with this work; if not, write to the Free Software Foundation,
  17  * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
  18  *
  19  * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
  20  * or visit www.oracle.com if you need additional information or have any
  21  * questions.
  22  */
  23 
  24 /**
  25  * NASHORN-525 : nashorn misses security access checks
  26  *
  27  * @test
  28  * @run
  29  */
  30 
  31 function check(code) {
  32     try {
  33         eval(code);
  34         fail("SecurityException expected for : " + code);
  35     } catch (e) {
  36         if (! (e instanceof java.lang.SecurityException)) {
  37             fail("SecurityException expected, but got " + e);
  38         }
  39     }
  40 }
  41 
  42 // if security manager is absent, pass the test vacuously.
  43 if (java.lang.System.getSecurityManager() != null) {
  44     // try accessing class from 'sun.*' packages
  45     check("Packages.sun.misc.Unsafe");
  46     check("Java.type('sun.misc.Unsafe')");
  47 
  48     // TODO this works in Java8 but not in Java8, disabling for now
  49     check("java.lang.Class.forName('sun.misc.Unsafe')");
  50 
  51     // try System.exit and System.loadLibrary
  52     check("java.lang.System.exit(0)");
  53     check("java.lang.System.loadLibrary('foo')");
  54 }