Skip to main content

Network System Access

Simple Story

This is the short list of numbers a pupil may telephone from the room.

Each entry names who may be rung and on which line, then says whether the pupil may dial at all, whether they may speak, and whether they may listen. Being allowed to place the call is not permission to say anything once it connects.

Position in the example policy file

The section documented on this page is marked in red. Every page in this section shows the same example file, so reading them in order walks it from top to bottom.

security-policy.yaml
thisPolicyFileCompliesToThePolicyVersion: 1
regardingTheSupervisedCode:
theFollowingProgrammingLanguageConfigurationIsUsed: JAVA_USING_MAVEN_WALA_AND_ASPECTJ
theSupervisedCodeUsesTheFollowingPackage: "org.example"
theMainClassInsideThisPackageIs: "Main"

theFollowingClassesAreTestClasses:
- "org.example.PenguinTest"

theFollowingResourceAccessesArePermitted:

regardingFileSystemInteractions:
- onThisPathAndAllPathsBelow: "something.txt"
readAllFiles: true
overwriteAllFiles: true
createAllFiles: true
executeAllFiles: false
deleteAllFiles: false

regardingNetworkConnections:
- onTheHost: "www.example.com"
onThePort: 80
openConnections: true
sendData: true
receiveData: true

regardingCommandExecutions:
- executeTheCommand: "ls"
withTheseArguments:
- "-l"

regardingThreadCreations:
- createTheFollowingNumberOfThreads: 10
ofThisClass: "org.example.Worker"

regardingPackageImports:
- importTheFollowingPackage: "java.util"

regardingTimeouts:
- timeout: 120000

Fields

Implemented by NetworkPermission in policy/policySubComponents/NetworkPermission.java.

FieldDatatypeExplanationExampleRegex or Range
onTheHostStringThe host this entry governs.www.example.comHOST_PATTERN: *, localhost, an IPv4 address, an IPv6 address (including IPv4-mapped forms), or a Domain Name System (DNS) name of at most 253 characters whose labels are at most 63 characters. A bare four-part numeric string is rejected as a DNS name so that it must parse as an IP address.
onThePortintThe port this entry governs. 0 is the any-port wildcard.80Range 065535 inclusive. Outside that range the constructor throws.
openConnectionsbooleanPermits opening a connection to the host and port.truetrue or false. Required: an entry that omits it is rejected on load.
sendDatabooleanPermits sending data on the connection.truetrue or false. Required: an entry that omits it is rejected on load.
receiveDatabooleanPermits receiving data on the connection.truetrue or false. Required: an entry that omits it is rejected on load.

Notes

All five fields are required. SecurityPolicySchemaValidator passes the network field set as both the accepted and the required set, so an entry that leaves a boolean out is rejected when the policy is loaded rather than read as a denial. Write false explicitly for every operation the entry does not permit.

Port 0 is the only any-port wildcard. There is no range syntax.

A narrow allowance stays narrow at runtime even though the architecture layer cannot represent it: static analysis is argument-insensitive, so it sees only that a connection may be opened, while the aspect-oriented programming (AOP) layer checks the actual host and port of the call.