diff --git a/server/src/main/resources/org/opensearch/bootstrap/security.policy b/server/src/main/resources/org/opensearch/bootstrap/security.policy index fbe0afb3c2a95..d51165898602f 100644 --- a/server/src/main/resources/org/opensearch/bootstrap/security.policy +++ b/server/src/main/resources/org/opensearch/bootstrap/security.policy @@ -91,30 +91,37 @@ grant codeBase "${codebase.zstd-jni}" { // repository-azure plugin and server side streaming grant codeBase "${codebase.reactor-core}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.opensearch-cli}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.opensearch-core}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.jackson-core}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.opensearch-common}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.opensearch-x-content}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.opensearch}" { permission java.net.SocketPermission "*", "connect,resolve"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; //// Everything else: diff --git a/server/src/main/resources/org/opensearch/bootstrap/test-framework.policy b/server/src/main/resources/org/opensearch/bootstrap/test-framework.policy index 5fe1a5b64e6c7..04af165708511 100644 --- a/server/src/main/resources/org/opensearch/bootstrap/test-framework.policy +++ b/server/src/main/resources/org/opensearch/bootstrap/test-framework.policy @@ -81,6 +81,7 @@ grant codeBase "${codebase.lucene-test-framework}" { permission java.nio.file.LinkPermission "hard"; // needed for RAMUsageTester permission java.lang.RuntimePermission "accessDeclaredMembers"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.randomizedtesting-runner}" { @@ -92,6 +93,7 @@ grant codeBase "${codebase.randomizedtesting-runner}" { permission org.opensearch.secure_sm.ThreadPermission "modifyArbitraryThreadGroup"; // needed for TestClass creation permission java.lang.RuntimePermission "accessDeclaredMembers"; + permission java.net.NetPermission "accessUnixDomainSocket"; }; grant codeBase "${codebase.junit}" { @@ -176,4 +178,5 @@ grant { permission org.opensearch.secure_sm.ThreadContextPermission "stashAndMergeHeaders"; permission org.opensearch.secure_sm.ThreadContextPermission "stashWithOrigin"; permission java.lang.RuntimePermission "setDefaultUncaughtExceptionHandler"; + permission java.net.NetPermission "accessUnixDomainSocket"; };