Java: problem creating/executing UDR
Posted in 2009
Topics: Installation, Setup & Upgrades, Stored Procedures & SPL, Server Administration, Security, Permissions & Auditing, Data Types & Schema Design, Java & JDBC Development
I hope I'm posting this to the correct group.
Please, does anybody know what's going on and what I can do to fix this?
IBM Informix Dynamic Server Version 10.00.FC8
This is the script I used to setup my java environment:
=======================================
$ more java_env.sh
export JAVA_BINDIR=/opt/java1.4/bin
export JAVA_HOME=/opt/java1.4
export JAVA_ROOT=/opt/java1.4
export PATH=/opt/java1.4/bin:$PATH
=======================================
I successfully installed my jar using dbaccess:
EXECUTE PROCEDURE install_jar(
"file:/home/informix/extend/udr/utilitiesUDR.jar",
"utilitiesudr_jar",0);
Then created sendmail udr:
CREATE FUNCTION sendmail (p_exe varchar(64),
p_flag char(2),
p_subject varchar(64),
p_sendlist varchar(255),
p_body varchar(255)) RETURNING INT;
EXTERNAL NAME 'utilitiesudr_jar:gov.utah.dps.utilities.Email.sendmail'
LANGUAGE JAVA;
I'm not really sure what this does but I saw it somewhere and it seemed like a
good idea:
ALTER FUNCTION sendmail WITH (ADD HANDLESNULLS);
So when I execute sendmail in dbaccess:
EXECUTE FUNCTION sendmail('/usr/bin/mailx','-s','Test Subject','bkennedy@utah.gov,bkennedy','Test Msg Body');
I get:
(38000) - Unknown throwable: (java.lang.SecurityException: Java UDR/Solano Ap
I have edited my informix.policy but still can't get it to work. Here is the
current contents of /home/informix/extend/krakatoa/informix.policy:
=======================================
// informix security policy
// dummy policy
// informix default policy as follows:
grant codeBase "file:$(JVPHOME)/-"{
permission java.security.AllPermission;
};
grant codeBase "file:/home/informix/extend/udr/utilitiesudr.jar"{
permission java.security.AllPermission;
};
grant {
permission java.util.PropertyPermission "user.language", "write";
permission java.security.SecurityPermission "getPolicy";
permission java.net.NetPermission "specifyStreamHandler";
permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
};
// users can add their security policy in ${JVPHOME}/informix.policy.
=======================================
I've googled 'informix.policy' but don't seem to be getting anywhere.
Here's the java portion of the onconfig:
=======================================
VPCLASS jvp,num=1 # Number of JVPs to start with
JVPJAVAHOME /home/informix/extend/krakatoa/jre # JRE installation root
directory
JVPHOME /home/informix/extend/krakatoa # Krakatoa installation directory
JVPPROPFILE /home/informix/extend/krakatoa/.jvpprops # JVP property file
JVPLOGFILE /home/informix/jvp.log # JVP log file.
JDKVERSION 1.4 # JDK version supported by this server
# The path to the JRE libraries relative to JVPJAVAHOME
#JVPJAVALIB /lib/PA_RISC2.0W
JVPJAVALIB /bin/
# The JRE libraries to use for the Java VM
JVPJAVAVM hpi:server:java:net:zip:jpeg
# use JVPARGS to change Java VM configuration
#To display jni call
#JVPARGS -verbose:jni
JVPARGS -Djava.security.policy=/home/informix/extend/krakatoa/informix.policy
=======================================
Here's my java code:
=======================================
package gov.utah.dps.utilities;
import java.io.*;
public class Email {
public static int sendmail(String exe, String flag, String subject, String
sendlist , String body){
String[] cmd = new String[]{exe,flag,subject,sendlist};
for (int i=0; i<cmd.length; i++) System.out.println(cmd[i]);
return sendmail(cmd, body);
}
public static int sendmail(String[] cmd, String body) {
try {
Process p = Runtime.getRuntime().exec(cmd);
OutputStreamWriter osw = new OutputStreamWriter(p.getOutputStream(), "8859_1");
osw.write(body);
osw.flush();
/* When mailx is done reading it will receive an EOF from this close. */
osw.close();
/* Wait for the mailx process to complete. Completion is exit.*/
return p.waitFor();
}catch(IOException e){
System.err.println("class
Email:IOException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -1;
}catch(InterruptedException e){
System.err.println("class
Email:InterruptedException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -2;
}
}
public static void main(String[] args){
String exe = "/usr/bin/mailx";
String flag="-s";
String subject="Test Subject";
String sendlist="bkennedy@utah.gov,bkennedy";
String body="Test Msg Body";
System.out.println(sendmail(exe,flag,subject,sendlist,body));
}
}
=======================================
Hi Bevis,
The problem might be:
Process p = Runtime.getRuntime().exec(cmd);
You are not allowed to execute a process in a Java UDR as it can mess up the
process address space (though you could call a SPL stored procedure that
executes the SYSTEM command if you really wanted to).
Instead of creating a process that calls "/usr/bin/mailx", why not call the
Java Mail API directly? http://java.sun.com/products/javamail/ - you'd
probably end up with less code.
Regards
Guy
________________________________
From: Bevis Kennedy <bkennedy@utah.gov>
To: ids@iiug.org
Sent: Thursday, February 5, 2009 2:29:34 PM
Subject: Java: problem creating/executing UDR [14780]
I hope I'm posting this to the correct group.
Please, does anybody know what's going on and what I can do to fix this?
IBM Informix Dynamic Server Version 10.00.FC8
This is the script I used to setup my java environment:
=======================================
$ more java_env.sh
export JAVA_BINDIR=/opt/java1.4/bin
export JAVA_HOME=/opt/java1.4
export JAVA_ROOT=/opt/java1.4
export PATH=/opt/java1.4/bin:$PATH
=======================================
I successfully installed my jar using dbaccess:
EXECUTE PROCEDURE install_jar(
"file:/home/informix/extend/udr/utilitiesUDR.jar",
"utilitiesudr_jar",0);
Then created sendmail udr:
CREATE FUNCTION sendmail (p_exe varchar(64),
p_flag char(2),
p_subject varchar(64),
p_sendlist varchar(255),
p_body varchar(255)) RETURNING INT;
EXTERNAL NAME 'utilitiesudr_jar:gov.utah.dps.utilities.Email.sendmail'
LANGUAGE JAVA;
I'm not really sure what this does but I saw it somewhere and it seemed like a
good idea:
ALTER FUNCTION sendmail WITH (ADD HANDLESNULLS);
So when I execute sendmail in dbaccess:
EXECUTE FUNCTION sendmail('/usr/bin/mailx','-s','Test Subject','bkennedy@utah.gov,bkennedy','Test Msg Body');
I get:
(38000) - Unknown throwable: (java.lang.SecurityException: Java UDR/Solano Ap
I have edited my informix.policy but still can't get it to work. Here is the
current contents of /home/informix/extend/krakatoa/informix.policy:
=======================================
// informix security policy
// dummy policy
// informix default policy as follows:
grant codeBase "file:$(JVPHOME)/-"{
permission java.security.AllPermission;
};
grant codeBase "file:/home/informix/extend/udr/utilitiesudr.jar"{
permission java.security.AllPermission;
};
grant {
permission java.util.PropertyPermission "user.language", "write";
permission java.security.SecurityPermission "getPolicy";
permission java.net.NetPermission "specifyStreamHandler";
permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
};
// users can add their security policy in ${JVPHOME}/informix.policy.
=======================================
I've googled 'informix.policy' but don't seem to be getting anywhere.
Here's the java portion of the onconfig:
=======================================
VPCLASS jvp,num=1 # Number of JVPs to start with
JVPJAVAHOME /home/informix/extend/krakatoa/jre # JRE installation root
directory
JVPHOME /home/informix/extend/krakatoa # Krakatoa installation directory
JVPPROPFILE /home/informix/extend/krakatoa/.jvpprops # JVP property file
JVPLOGFILE /home/informix/jvp.log # JVP log file.
JDKVERSION 1.4 # JDK version supported by this server
# The path to the JRE libraries relative to JVPJAVAHOME
#JVPJAVALIB /lib/PA_RISC2.0W
JVPJAVALIB /bin/
# The JRE libraries to use for the Java VM
JVPJAVAVM hpi:server:java:net:zip:jpeg
# use JVPARGS to change Java VM configuration
#To display jni call
#JVPARGS -verbose:jni
JVPARGS -Djava.security.policy=/home/informix/extend/krakatoa/informix.policy
=======================================
Here's my java code:
=======================================
package gov.utah.dps.utilities;
import java.io.*;
public class Email {
public static int sendmail(String exe, String flag, String subject, String
sendlist , String body){
String[] cmd = new String[]{exe,flag,subject,sendlist};
for (int i=0; i<cmd.length; i++) System.out.println(cmd[i]);
return sendmail(cmd, body);
}
public static int sendmail(String[] cmd, String body) {
try {
Process p = Runtime.getRuntime().exec(cmd);
OutputStreamWriter osw = new OutputStreamWriter(p.getOutputStream(),
"8859_1");
osw.write(body);
osw.flush();
/* When mailx is done reading it will receive an EOF from this close. */
osw.close();
/* Wait for the mailx process to complete. Completion is exit.*/
return p.waitFor();
}catch(IOException e){
System.err.println("class
Email:IOException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -1;
}catch(InterruptedException e){
System.err.println("class
Email:InterruptedException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -2;
}
}
public static void main(String[] args){
String exe = "/usr/bin/mailx";
String flag="-s";
String subject="Test Subject";
String sendlist="bkennedy@utah.gov,bkennedy";
String body="Test Msg Body";
System.out.println(sendmail(exe,flag,subject,sendlist,body));
}
}
=======================================
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks Guy,
I used the "/usr/bin/mailx" because I have used it in the past for cron jobs
and it always worked. With this project I need to send an email from a trigger.
When a row is inserted in the table I check the state of the 'is_approved'
flag. If the flag is 'f' I query another database to find out who has approval
authorization and send them an email notification that an approval is pending
and the details. So it seems to me I have to use a SPL, UDR or combination of
both.
I created a java mail client that tests ok but when I create an UDR I get the
same 38000 error. Is there anyway to tell Informix that this particular UDR
has the correct permissions to execute?
I can send the java code and implementation details if it will help.
Regards,
Bevis
>>> "Guy ." <gbowerman@yahoo.com> 02/05/09 5:07 PM >>>
Hi Bevis,
The problem might be:
Process p = Runtime.getRuntime().exec(cmd);
You are not allowed to execute a process in a Java UDR as it can mess up the
process address space (though you could call a SPL stored procedure that
executes the SYSTEM command if you really wanted to).
Instead of creating a process that calls "/usr/bin/mailx", why not call the
Java Mail API directly? http://java.sun.com/products/javamail/ - you'd
probably end up with less code.
Regards
Guy
________________________________
From: Bevis Kennedy <bkennedy@utah.gov>
To: ids@iiug.org
Sent: Thursday, February 5, 2009 2:29:34 PM
Subject: Java: problem creating/executing UDR [14780]
I hope I'm posting this to the correct group.
Please, does anybody know what's going on and what I can do to fix this?
IBM Informix Dynamic Server Version 10.00.FC8
This is the script I used to setup my java environment:
=======================================
$ more java_env.sh
export JAVA_BINDIR=/opt/java1.4/bin
export JAVA_HOME=/opt/java1.4
export JAVA_ROOT=/opt/java1.4
export PATH=/opt/java1.4/bin:$PATH
=======================================
I successfully installed my jar using dbaccess:
EXECUTE PROCEDURE install_jar(
"file:/home/informix/extend/udr/utilitiesUDR.jar",
"utilitiesudr_jar",0);
Then created sendmail udr:
CREATE FUNCTION sendmail (p_exe varchar(64),
p_flag char(2),
p_subject varchar(64),
p_sendlist varchar(255),
p_body varchar(255)) RETURNING INT;
EXTERNAL NAME 'utilitiesudr_jar:gov.utah.dps.utilities.Email.sendmail'
LANGUAGE JAVA;
I'm not really sure what this does but I saw it somewhere and it seemed like a
good idea:
ALTER FUNCTION sendmail WITH (ADD HANDLESNULLS);
So when I execute sendmail in dbaccess:
EXECUTE FUNCTION sendmail('/usr/bin/mailx','-s','Test Subject','bkennedy@utah.gov,bkennedy','Test Msg Body');
I get:
(38000) - Unknown throwable: (java.lang.SecurityException: Java UDR/Solano Ap
I have edited my informix.policy but still can't get it to work. Here is the
current contents of /home/informix/extend/krakatoa/informix.policy:
=======================================
// informix security policy
// dummy policy
// informix default policy as follows:
grant codeBase "file:$(JVPHOME)/-"{
permission java.security.AllPermission;
};
grant codeBase "file:/home/informix/extend/udr/utilitiesudr.jar"{
permission java.security.AllPermission;
};
grant {
permission java.util.PropertyPermission "user.language", "write";
permission java.security.SecurityPermission "getPolicy";
permission java.net.NetPermission "specifyStreamHandler";
permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
};
// users can add their security policy in ${JVPHOME}/informix.policy.
=======================================
I've googled 'informix.policy' but don't seem to be getting anywhere.
Here's the java portion of the onconfig:
=======================================
VPCLASS jvp,num=1 # Number of JVPs to start with
JVPJAVAHOME /home/informix/extend/krakatoa/jre # JRE installation root
directory
JVPHOME /home/informix/extend/krakatoa # Krakatoa installation directory
JVPPROPFILE /home/informix/extend/krakatoa/.jvpprops # JVP property file
JVPLOGFILE /home/informix/jvp.log # JVP log file.
JDKVERSION 1.4 # JDK version supported by this server
# The path to the JRE libraries relative to JVPJAVAHOME
#JVPJAVALIB /lib/PA_RISC2.0W
JVPJAVALIB /bin/
# The JRE libraries to use for the Java VM
JVPJAVAVM hpi:server:java:net:zip:jpeg
# use JVPARGS to change Java VM configuration
#To display jni call
#JVPARGS -verbose:jni
JVPARGS -Djava.security.policy=/home/informix/extend/krakatoa/informix.policy
=======================================
Here's my java code:
=======================================
package gov.utah.dps.utilities;
import java.io.*;
public class Email {
public static int sendmail(String exe, String flag, String subject, String
sendlist , String body){
String[] cmd = new String[]{exe,flag,subject,sendlist};
for (int i=0; i<cmd.length; i++) System.out.println(cmd[i]);
return sendmail(cmd, body);
}
public static int sendmail(String[] cmd, String body) {
try {
Process p = Runtime.getRuntime().exec(cmd);
OutputStreamWriter osw = new OutputStreamWriter(p.getOutputStream(),
"8859_1");
osw.write(body);
osw.flush();
/* When mailx is done reading it will receive an EOF from this close. */
osw.close();
/* Wait for the mailx process to complete. Completion is exit.*/
return p.waitFor();
}catch(IOException e){
System.err.println("class
Email:IOException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -1;
}catch(InterruptedException e){
System.err.println("class
Email:InterruptedException:"+e.getMessage()+"\\
"+e.getStackTrace());
return -2;
}
}
public static void main(String[] args){
String exe = "/usr/bin/mailx";
String flag="-s";
String subject="Test Subject";
String sendlist="bkennedy@utah.gov,bkennedy";
String body="Test Msg Body";
System.out.println(sendmail(exe,flag,subject,sendlist,body));
}
}
=======================================
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.