Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-23 Thread Ron Pressler
> On 23 Jun 2023, at 08:16, Peter Firmstone wrote: > > > When someone comes up with a simpler design, I'm all up for the effectiveness > challenge, I'm pretty sure that whatever it is, we'll blow it away both on > performance and effectiveness, we've had years to perfect it, but I would >

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-23 Thread Peter Firmstone
On 23/06/2023 11:06 am, Ron Pressler wrote: On 22 Jun 2023, at 23:50, Peter Firmstone wrote: If you are able to share, I'd be interested to learn about challenges you had with SM, if we one day have the opportunity to reimplement it, the lessons might be valuable, so we can avoid the

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-22 Thread Ron Pressler
> On 22 Jun 2023, at 23:50, Peter Firmstone wrote: > > > If you are able to share, I'd be interested to learn about challenges you had > with SM, if we one day have the opportunity to reimplement it, the lessons > might be valuable, so we can avoid the same mistakes. Much of the effort has

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-22 Thread Peter Firmstone
eter Firmstone *Cc:* c...@anastigmatix.net ; security-dev@openjdk.org *Subject:* Re: [External] : Re: PrivilegedAction et al and JEP411 > On 21 Jun 2023, at 01:36, Peter Firmstone wrote: > > > I'm just disappointed that we are being prevented from reimplementing a replacement authorizat

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-22 Thread Erik Gahlin
ity-dev on behalf of Ron Pressler Sent: Wednesday, June 21, 2023 12:52 PM To: Peter Firmstone Cc: c...@anastigmatix.net ; security-dev@openjdk.org Subject: Re: [External] : Re: PrivilegedAction et al and JEP411 > On 21 Jun 2023, at 01:36, Peter Firmstone wrote: > > > I'm ju

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-22 Thread Ron Pressler
> On 22 Jun 2023, at 02:21, Peter Firmstone wrote: > > This discussion on OpenSearch is worth a read. > https://github.com/opensearch-project/OpenSearch/issues/1687 The cross-platform API (SystemCallFilter) is something that looks like it would make for an interesting separate library. I

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-21 Thread Peter Firmstone
On 21/06/2023 8:52 pm, Ron Pressler wrote: On 21 Jun 2023, at 01:36, Peter Firmstone wrote: I'm just disappointed that we are being prevented from reimplementing a replacement authorization layer in Java, without any compromise from OpenJDK it's not possible. We at least need to retain

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-21 Thread Ron Pressler
> On 21 Jun 2023, at 01:36, Peter Firmstone wrote: > > > I'm just disappointed that we are being prevented from reimplementing a > replacement authorization layer in Java, without any compromise from OpenJDK > it's not possible. We at least need to retain some kind of privilege action >

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-20 Thread Peter Firmstone
On 20/06/2023 9:04 pm, Ron Pressler wrote: On 20 Jun 2023, at 06:26, Peter Firmstone wrote: Don't get me wrong, it's good that OpenJDK is improving encapsulation, it's just OpenJDK is also undoing years of tested and hardened API's, You probably meant that as a bad thing, but I read it as

Re: [External] : Re: PrivilegedAction et al and JEP411

2023-06-20 Thread Ron Pressler
> On 20 Jun 2023, at 06:26, Peter Firmstone wrote: > > Don't get me wrong, it's good that OpenJDK is improving encapsulation, it's > just OpenJDK is also undoing years of tested and hardened API's, You probably meant that as a bad thing, but I read it as thank you for serving your users!