Class AdminPermission

  • All Implemented Interfaces:
    java.io.Serializable, java.security.Guard

    public final class AdminPermission
    extends java.security.BasicPermission
    A bundle's authority to perform specific privileged administrative operations on or to get sensitive information about a bundle. The actions for this permission are:
     Action             Methods
     class              Bundle.loadClass
     execute            Bundle.start
                        Bundle.stop
                        BundleStartLevel.setStartLevel
     extensionLifecycle BundleContext.installBundle for extension bundles
                        Bundle.update for extension bundles
                        Bundle.uninstall for extension bundles
     lifecycle          BundleContext.installBundle
                        Bundle.update
                        Bundle.uninstall
     listener           BundleContext.addBundleListener for
                          SynchronousBundleListener
                        BundleContext.removeBundleListener for
                          SynchronousBundleListener
     metadata           Bundle.getHeaders
                        Bundle.getLocation
     resolve            FrameworkWiring.refreshBundles
                        FrameworkWiring.resolveBundles
     resource           Bundle.getResource
                        Bundle.getResources
                        Bundle.getEntry
                        Bundle.getEntryPaths
                        Bundle.findEntries
                        Bundle resource/entry URL creation
     startlevel         FrameworkStartLevel.setStartLevel
                        FrameworkStartLevel.setInitialBundleStartLevel
     context            Bundle.getBundleContext
     weave              WovenClass.getBytes
                        WovenClass.setBytes
                        WovenClass.getDynamicImports for modification
     

    The special action "*" will represent all actions. The resolve action is implied by the class, execute and resource actions.

    The name of this permission is a filter expression. The filter gives access to the following attributes:

    • signer - A Distinguished Name chain used to sign a bundle. Wildcards in a DN are not matched according to the filter string rules, but according to the rules defined for a DN chain.
    • location - The location of a bundle.
    • id - The bundle ID of the designated bundle.
    • name - The symbolic name of a bundle.
    Filter attribute names are processed in a case sensitive manner.
    See Also:
    Serialized Form
    • Field Summary

      Fields 
      Modifier and Type Field Description
      private static int ACTION_ALL  
      private static int ACTION_CLASS  
      private static int ACTION_CONTEXT  
      private static int ACTION_EXECUTE  
      private static int ACTION_EXTENSIONLIFECYCLE  
      private static int ACTION_LIFECYCLE  
      private static int ACTION_LISTENER  
      (package private) int action_mask
      The actions mask.
      private static int ACTION_METADATA  
      (package private) static int ACTION_NONE  
      private static int ACTION_RESOLVE  
      private static int ACTION_RESOURCE  
      private static int ACTION_STARTLEVEL  
      private static int ACTION_WEAVE  
      private java.lang.String actions
      The actions in canonical form.
      (package private) Bundle bundle
      The bundle governed by this AdminPermission - only used if filter == null
      static java.lang.String CLASS
      The action string class.
      static java.lang.String CONTEXT
      The action string context.
      static java.lang.String EXECUTE
      The action string execute.
      static java.lang.String EXTENSIONLIFECYCLE
      The action string extensionLifecycle.
      (package private) Filter filter
      If this AdminPermission was constructed with a filter, this holds a Filter matching object used to evaluate the filter in implies.
      static java.lang.String LIFECYCLE
      The action string lifecycle.
      static java.lang.String LISTENER
      The action string listener.
      static java.lang.String METADATA
      The action string metadata.
      private java.util.Map<java.lang.String,​java.lang.Object> properties
      This map holds the properties of the permission, used to match a filter in implies.
      private static java.lang.ThreadLocal<Bundle> recurse
      ThreadLocal used to determine if we have recursively called getProperties.
      static java.lang.String RESOLVE
      The action string resolve.
      static java.lang.String RESOURCE
      The action string resource.
      (package private) static long serialVersionUID  
      static java.lang.String STARTLEVEL
      The action string startlevel.
      static java.lang.String WEAVE
      The action string weave.
    • Constructor Summary

      Constructors 
      Constructor Description
      AdminPermission()
      Creates a new AdminPermission object that matches all bundles and has all actions.
      AdminPermission​(java.lang.String filter, java.lang.String actions)
      Create a new AdminPermission.
      AdminPermission​(Bundle bundle, java.lang.String actions)
      Creates a new requested AdminPermission object to be used by the code that must perform checkPermission.
      AdminPermission​(Filter filter, int mask)
      Package private constructor used by AdminPermissionCollection.
    • Method Summary

      All Methods Static Methods Instance Methods Concrete Methods 
      Modifier and Type Method Description
      private static java.lang.String createName​(Bundle bundle)
      Create a permission name from a Bundle
      boolean equals​(java.lang.Object obj)
      Determines the equality of two AdminPermission objects.
      java.lang.String getActions()
      Returns the canonical string representation of the AdminPermission actions.
      private java.util.Map<java.lang.String,​java.lang.Object> getProperties()
      Called by implies0 on an AdminPermission which was constructed with a Bundle.
      int hashCode()
      Returns the hash code value for this object.
      boolean implies​(java.security.Permission p)
      Determines if the specified permission is implied by this object.
      (package private) boolean implies0​(AdminPermission requested, int effective)
      Internal implies method.
      java.security.PermissionCollection newPermissionCollection()
      Returns a new PermissionCollection object suitable for storing AdminPermissions.
      private static int parseActions​(java.lang.String actions)
      Parse action string into action mask.
      private static Filter parseFilter​(java.lang.String filterString)
      Parse filter string into a Filter object.
      private void readObject​(java.io.ObjectInputStream s)
      readObject is called to restore the state of this permission from a stream.
      private void setTransients​(Filter filter, int mask)
      Called by constructors and when deserialized.
      private void writeObject​(java.io.ObjectOutputStream s)
      WriteObject is called to save the state of this permission object to a stream.
      • Methods inherited from class java.security.Permission

        checkGuard, getName, toString
      • Methods inherited from class java.lang.Object

        clone, finalize, getClass, notify, notifyAll, wait, wait, wait
    • Field Detail

      • CLASS

        public static final java.lang.String CLASS
        The action string class. The class action implies the resolve action.
        Since:
        1.3
        See Also:
        Constant Field Values
      • EXECUTE

        public static final java.lang.String EXECUTE
        The action string execute. The execute action implies the resolve action.
        Since:
        1.3
        See Also:
        Constant Field Values
      • EXTENSIONLIFECYCLE

        public static final java.lang.String EXTENSIONLIFECYCLE
        The action string extensionLifecycle.
        Since:
        1.3
        See Also:
        Constant Field Values
      • LIFECYCLE

        public static final java.lang.String LIFECYCLE
        The action string lifecycle.
        Since:
        1.3
        See Also:
        Constant Field Values
      • LISTENER

        public static final java.lang.String LISTENER
        The action string listener.
        Since:
        1.3
        See Also:
        Constant Field Values
      • METADATA

        public static final java.lang.String METADATA
        The action string metadata.
        Since:
        1.3
        See Also:
        Constant Field Values
      • RESOLVE

        public static final java.lang.String RESOLVE
        The action string resolve. The resolve action is implied by the class, execute and resource actions.
        Since:
        1.3
        See Also:
        Constant Field Values
      • RESOURCE

        public static final java.lang.String RESOURCE
        The action string resource. The resource action implies the resolve action.
        Since:
        1.3
        See Also:
        Constant Field Values
      • STARTLEVEL

        public static final java.lang.String STARTLEVEL
        The action string startlevel.
        Since:
        1.3
        See Also:
        Constant Field Values
      • CONTEXT

        public static final java.lang.String CONTEXT
        The action string context.
        Since:
        1.4
        See Also:
        Constant Field Values
      • WEAVE

        public static final java.lang.String WEAVE
        The action string weave.
        Since:
        1.6
        See Also:
        Constant Field Values
      • ACTION_EXTENSIONLIFECYCLE

        private static final int ACTION_EXTENSIONLIFECYCLE
        See Also:
        Constant Field Values
      • actions

        private volatile java.lang.String actions
        The actions in canonical form.
      • action_mask

        transient int action_mask
        The actions mask.
      • filter

        transient Filter filter
        If this AdminPermission was constructed with a filter, this holds a Filter matching object used to evaluate the filter in implies.
      • bundle

        final transient Bundle bundle
        The bundle governed by this AdminPermission - only used if filter == null
      • properties

        private transient volatile java.util.Map<java.lang.String,​java.lang.Object> properties
        This map holds the properties of the permission, used to match a filter in implies. This is not initialized until necessary, and then cached in this object.
      • recurse

        private static final java.lang.ThreadLocal<Bundle> recurse
        ThreadLocal used to determine if we have recursively called getProperties.
    • Constructor Detail

      • AdminPermission

        public AdminPermission()
        Creates a new AdminPermission object that matches all bundles and has all actions. Equivalent to AdminPermission("*","*");
      • AdminPermission

        public AdminPermission​(java.lang.String filter,
                               java.lang.String actions)
        Create a new AdminPermission. This constructor must only be used to create a permission that is going to be checked.

        Examples:

         (signer=\*,o=ACME,c=US)
         (&(signer=\*,o=ACME,c=US)(name=com.acme.*)
           (location=http://www.acme.com/bundles/*))
         (id>=1)
         

        When a signer key is used within the filter expression the signer value must escape the special filter chars ('*', '(', ')').

        Null arguments are equivalent to "*".

        Parameters:
        filter - A filter expression that can use signer, location, id, and name keys. A value of "*" or null matches all bundle. Filter attribute names are processed in a case sensitive manner.
        actions - class, execute, extensionLifecycle , lifecycle, listener, metadata, resolve , resource, startlevel, context or weave. A value of "*" or null indicates all actions.
        Throws:
        java.lang.IllegalArgumentException - If the filter has an invalid syntax.
      • AdminPermission

        public AdminPermission​(Bundle bundle,
                               java.lang.String actions)
        Creates a new requested AdminPermission object to be used by the code that must perform checkPermission. AdminPermission objects created with this constructor cannot be added to an AdminPermission permission collection.
        Parameters:
        bundle - A bundle.
        actions - class, execute, extensionLifecycle , lifecycle, listener, metadata, resolve , resource, startlevel, context, weave. A value of "*" or null indicates all actions.
        Since:
        1.3
      • AdminPermission

        AdminPermission​(Filter filter,
                        int mask)
        Package private constructor used by AdminPermissionCollection.
        Parameters:
        filter - name filter or null for wildcard.
        mask - action mask
    • Method Detail

      • createName

        private static java.lang.String createName​(Bundle bundle)
        Create a permission name from a Bundle
        Parameters:
        bundle - Bundle to use to create permission name.
        Returns:
        permission name.
      • setTransients

        private void setTransients​(Filter filter,
                                   int mask)
        Called by constructors and when deserialized.
        Parameters:
        filter - Permission's filter or null for wildcard.
        mask - action mask
      • parseActions

        private static int parseActions​(java.lang.String actions)
        Parse action string into action mask.
        Parameters:
        actions - Action string.
        Returns:
        action mask.
      • parseFilter

        private static Filter parseFilter​(java.lang.String filterString)
        Parse filter string into a Filter object.
        Parameters:
        filterString - The filter string to parse.
        Returns:
        a Filter for this bundle. If the specified filterString is null or equals "*", then null is returned to indicate a wildcard.
        Throws:
        java.lang.IllegalArgumentException - If the filter syntax is invalid.
      • implies

        public boolean implies​(java.security.Permission p)
        Determines if the specified permission is implied by this object. This method throws an exception if the specified permission was not constructed with a bundle.

        This method returns true if the specified permission is an AdminPermission AND

        • this object's filter matches the specified permission's bundle ID, bundle symbolic name, bundle location and bundle signer distinguished name chain OR
        • this object's filter is "*"
        AND this object's actions include all of the specified permission's actions.

        Special case: if the specified permission was constructed with "*" filter, then this method returns true if this object's filter is "*" and this object's actions include all of the specified permission's actions

        Overrides:
        implies in class java.security.BasicPermission
        Parameters:
        p - The requested permission.
        Returns:
        true if the specified permission is implied by this object; false otherwise.
      • implies0

        boolean implies0​(AdminPermission requested,
                         int effective)
        Internal implies method. Used by the implies and the permission collection implies methods.
        Parameters:
        requested - The requested AdminPermision which has already be validated as a proper argument. The requested AdminPermission must not have a filter expression.
        effective - The effective actions with which to start.
        Returns:
        true if the specified permission is implied by this object; false otherwise.
      • getActions

        public java.lang.String getActions()
        Returns the canonical string representation of the AdminPermission actions.

        Always returns present AdminPermission actions in the following order: class, execute, extensionLifecycle, lifecycle, listener, metadata, resolve, resource, startlevel, context, weave.

        Overrides:
        getActions in class java.security.BasicPermission
        Returns:
        Canonical string representation of the AdminPermission actions.
      • newPermissionCollection

        public java.security.PermissionCollection newPermissionCollection()
        Returns a new PermissionCollection object suitable for storing AdminPermissions.
        Overrides:
        newPermissionCollection in class java.security.BasicPermission
        Returns:
        A new PermissionCollection object.
      • equals

        public boolean equals​(java.lang.Object obj)
        Determines the equality of two AdminPermission objects.
        Overrides:
        equals in class java.security.BasicPermission
        Parameters:
        obj - The object being compared for equality with this object.
        Returns:
        true if obj is equivalent to this AdminPermission; false otherwise.
      • hashCode

        public int hashCode()
        Returns the hash code value for this object.
        Overrides:
        hashCode in class java.security.BasicPermission
        Returns:
        Hash code value for this object.
      • writeObject

        private void writeObject​(java.io.ObjectOutputStream s)
                          throws java.io.IOException
        WriteObject is called to save the state of this permission object to a stream. The actions are serialized, and the superclass takes care of the name.
        Throws:
        java.io.IOException
      • readObject

        private void readObject​(java.io.ObjectInputStream s)
                         throws java.io.IOException,
                                java.lang.ClassNotFoundException
        readObject is called to restore the state of this permission from a stream.
        Throws:
        java.io.IOException
        java.lang.ClassNotFoundException
      • getProperties

        private java.util.Map<java.lang.String,​java.lang.Object> getProperties()
        Called by implies0 on an AdminPermission which was constructed with a Bundle. This method loads a map with the filter-matchable properties of this bundle. The map is cached so this lookup only happens once. This method should only be called on an AdminPermission which was constructed with a bundle
        Returns:
        a map of properties for this bundle