Package org.osgi.service.subsystem
Class SubsystemPermission
java.lang.Object
java.security.Permission
java.security.BasicPermission
org.osgi.service.subsystem.SubsystemPermission
- All Implemented Interfaces:
Serializable
,Guard
A bundle's authority to perform specific privileged administrative operations
on or to get sensitive information about a subsystem. The actions for this
permission are:
Action Methods context Subsystem.getBundleContext execute Subsystem.start Subsystem.stop lifecycle Subsystem.install Subsystem.uninstall metadata Subsystem.getSubsystemHeaders Subsystem.getLocation
The name of this permission is a filter expression. The filter gives access to the following attributes:
- location - The location of a subsystem.
- id - The subsystem ID of the designated subsystem.
- name - The symbolic name of a subsystem.
- See Also:
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate static final int
private static final int
private static final int
private static final int
(package private) int
The actions mask.private static final int
(package private) static final int
private String
The actions in canonical form.static final String
The action stringcontext
.static final String
The action stringexecute
.(package private) org.osgi.framework.Filter
If this SubsystemPermission was constructed with a filter, this holds a Filter matching object used to evaluate the filter in implies.static final String
The action stringlifecycle
.static final String
The action stringmetadata
.This map holds the properties of the permission, used to match a filter in implies.private static final ThreadLocal
<Subsystem> ThreadLocal used to determine if we have recursively called getProperties.(package private) static final long
(package private) final Subsystem
The subsystem governed by this SubsystemPermission - only used if filter == null -
Constructor Summary
ConstructorsConstructorDescriptionSubsystemPermission
(String filter, String actions) Create a new SubsystemPermission.SubsystemPermission
(org.osgi.framework.Filter filter, int mask) Package private constructor used by SubsystemPermissionCollection.SubsystemPermission
(Subsystem subsystem, String actions) Creates a new requestedSubsystemPermission
object to be used by the code that must performcheckPermission
. -
Method Summary
Modifier and TypeMethodDescriptionprivate static String
createName
(Subsystem subsystem) Create a permission name from a Subsystemboolean
Determines the equality of twoSubsystemPermission
objects.Returns the canonical string representation of theSubsystemPermission
actions.Called byimplies0
on an SubsystemPermission which was constructed with a Subsystem.int
hashCode()
Returns the hash code value for this object.boolean
Determines if the specified permission is implied by this object.(package private) boolean
implies0
(SubsystemPermission requested, int effective) Internal implies method.Returns a newPermissionCollection
object suitable for storingSubsystemPermission
s.private static int
parseActions
(String actions) Parse action string into action mask.private static org.osgi.framework.Filter
parseFilter
(String filterString) Parse filter string into a Filter object.private void
readObject is called to restore the state of this permission from a stream.private void
setTransients
(org.osgi.framework.Filter filter, int mask) Called by constructors and when deserialized.private void
WriteObject is called to save the state of this permission object to a stream.Methods inherited from class java.security.Permission
checkGuard, getName, toString
-
Field Details
-
serialVersionUID
static final long serialVersionUID- See Also:
-
EXECUTE
The action stringexecute
.- See Also:
-
LIFECYCLE
The action stringlifecycle
.- See Also:
-
METADATA
The action stringmetadata
.- See Also:
-
CONTEXT
The action stringcontext
.- See Also:
-
ACTION_EXECUTE
private static final int ACTION_EXECUTE- See Also:
-
ACTION_LIFECYCLE
private static final int ACTION_LIFECYCLE- See Also:
-
ACTION_METADATA
private static final int ACTION_METADATA- See Also:
-
ACTION_CONTEXT
private static final int ACTION_CONTEXT- See Also:
-
ACTION_ALL
private static final int ACTION_ALL- See Also:
-
ACTION_NONE
static final int ACTION_NONE- See Also:
-
actions
The actions in canonical form. -
action_mask
transient int action_maskThe actions mask. -
filter
transient org.osgi.framework.Filter filterIf this SubsystemPermission was constructed with a filter, this holds a Filter matching object used to evaluate the filter in implies. -
subsystem
The subsystem governed by this SubsystemPermission - only used if filter == null -
properties
This map holds the properties of the permission, used to match a filter in implies. This is not initialized until necessary, and then cached in this object. -
recurse
ThreadLocal used to determine if we have recursively called getProperties.
-
-
Constructor Details
-
SubsystemPermission
Create a new SubsystemPermission. This constructor must only be used to create a permission that is going to be checked.Examples:
(name=com.acme.*)(location=http://www.acme.com/subsystems/*)) (id>=1)
- Parameters:
filter
- A filter expression that can use, location, id, and name keys. Filter attribute names are processed in a case sensitive manner. A special value of"*"
can be used to match all subsystems.actions
-execute
,lifecycle
,metadata
, orcontext
.- Throws:
IllegalArgumentException
- If the filter has an invalid syntax.
-
SubsystemPermission
Creates a new requestedSubsystemPermission
object to be used by the code that must performcheckPermission
.SubsystemPermission
objects created with this constructor cannot be added to anSubsystemPermission
permission collection.- Parameters:
subsystem
- A subsystem.actions
-execute
,lifecycle
,metadata
, orcontext
.
-
SubsystemPermission
SubsystemPermission(org.osgi.framework.Filter filter, int mask) Package private constructor used by SubsystemPermissionCollection.- Parameters:
filter
- name filter ornull
for wildcard.mask
- action mask
-
-
Method Details
-
createName
Create a permission name from a Subsystem- Parameters:
subsystem
- Subsystem to use to create permission name.- Returns:
- permission name.
-
setTransients
private void setTransients(org.osgi.framework.Filter filter, int mask) Called by constructors and when deserialized.- Parameters:
filter
- Permission's filter ornull
for wildcard.mask
- action mask
-
parseActions
Parse action string into action mask.- Parameters:
actions
- Action string.- Returns:
- action mask.
-
parseFilter
Parse filter string into a Filter object.- Parameters:
filterString
- The filter string to parse.- Returns:
- a Filter for this subsystem. If the specified filterString equals
"*", then
null
is returned to indicate a wildcard. - Throws:
IllegalArgumentException
- If the filter syntax is invalid.
-
implies
Determines if the specified permission is implied by this object. This method throws an exception if the specified permission was not constructed with a subsystem.This method returns
true
if the specified permission is a SubsystemPermission AND- this object's filter matches the specified permission's subsystem ID, subsystem symbolic name, and subsystem location OR
- this object's filter is "*"
Special case: if the specified permission was constructed with "*" filter, then this method returns
true
if this object's filter is "*" and this object's actions include all of the specified permission's actions- Overrides:
implies
in classBasicPermission
- Parameters:
p
- The requested permission.- Returns:
true
if the specified permission is implied by this object;false
otherwise.
-
implies0
Internal implies method. Used by the implies and the permission collection implies methods.- Parameters:
requested
- The requested SubsystemPermision which has already been validated as a proper argument. The requested SubsystemPermission must not have a filter expression.effective
- The effective actions with which to start.- Returns:
true
if the specified permission is implied by this object;false
otherwise.
-
getActions
Returns the canonical string representation of theSubsystemPermission
actions.Always returns present
SubsystemPermission
actions in the following order:execute
,lifecycle
,metadata
,context
.- Overrides:
getActions
in classBasicPermission
- Returns:
- Canonical string representation of the
SubsystemPermission
actions.
-
newPermissionCollection
Returns a newPermissionCollection
object suitable for storingSubsystemPermission
s.- Overrides:
newPermissionCollection
in classBasicPermission
- Returns:
- A new
PermissionCollection
object.
-
equals
Determines the equality of twoSubsystemPermission
objects.- Overrides:
equals
in classBasicPermission
- Parameters:
obj
- The object being compared for equality with this object.- Returns:
true
ifobj
is equivalent to thisSubsystemPermission
;false
otherwise.
-
hashCode
public int hashCode()Returns the hash code value for this object.- Overrides:
hashCode
in classBasicPermission
- Returns:
- Hash code value for this object.
-
writeObject
WriteObject is called to save the state of this permission object to a stream. The actions are serialized, and the superclass takes care of the name.- Throws:
IOException
-
readObject
readObject is called to restore the state of this permission from a stream.- Throws:
IOException
ClassNotFoundException
-
getProperties
Called byimplies0
on an SubsystemPermission which was constructed with a Subsystem. This method loads a map with the filter-matchable properties of this subsystem. The map is cached so this lookup only happens once. This method should only be called on an SubsystemPermission which was constructed with a subsystem- Returns:
- a map of properties for this subsystem
-