瀏覽代碼

[8.x] Enable entitlements by default (#122907) (#123401)

* Enable entitlements by default (#122907)

Entitlements are almost complete. This commit enables them by default,
in preparation for 8.18/9.0.

* mute test

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Ryan Ernst 7 月之前
父節點
當前提交
1c0fab466a

+ 1 - 1
distribution/tools/server-cli/src/main/java/org/elasticsearch/server/cli/SystemJvmOptions.java

@@ -28,7 +28,7 @@ final class SystemJvmOptions {
     static List<String> systemJvmOptions(Settings nodeSettings, final Map<String, String> sysprops) {
         String distroType = sysprops.get("es.distribution.type");
         boolean isHotspot = sysprops.getOrDefault("sun.management.compiler", "").contains("HotSpot");
-        boolean entitlementsExplicitlyEnabled = Booleans.parseBoolean(sysprops.getOrDefault("es.entitlements.enabled", "false"));
+        boolean entitlementsExplicitlyEnabled = Booleans.parseBoolean(sysprops.getOrDefault("es.entitlements.enabled", "true"));
         // java 24+ only supports entitlements, but it may be enabled on earlier versions explicitly
         boolean useEntitlements = RuntimeVersionFeature.isSecurityManagerAvailable() == false || entitlementsExplicitlyEnabled;
         return Stream.of(

+ 2 - 0
libs/entitlement/src/main/java/org/elasticsearch/entitlement/initialization/EntitlementInitialization.java

@@ -179,6 +179,7 @@ public class EntitlementInitialization {
         if (bootstrapArgs.pidFile() != null) {
             serverModuleFileDatas.add(FileData.ofPath(bootstrapArgs.pidFile(), READ_WRITE));
         }
+
         Collections.addAll(
             serverScopes,
             new Scope(
@@ -187,6 +188,7 @@ public class EntitlementInitialization {
                     new CreateClassLoaderEntitlement(),
                     new FilesEntitlement(
                         List.of(
+                            // TODO: what in es.base is accessing shared repo?
                             FileData.ofRelativePath(Path.of(""), SHARED_REPO, READ_WRITE),
                             FileData.ofRelativePath(Path.of(""), DATA, READ_WRITE)
                         )

+ 3 - 0
muted-tests.yml

@@ -459,3 +459,6 @@ tests:
 - class: org.elasticsearch.xpack.test.rest.XPackRestIT
   method: test {p0=data_stream/80_resolve_index_data_streams/Resolve index with hidden and closed indices}
   issue: https://github.com/elastic/elasticsearch/issues/123081
+- class: org.elasticsearch.analysis.common.CommonAnalysisClientYamlTestSuiteIT
+  method: test {yaml=analysis-common/40_token_filters/stemmer_override file access}
+  issue: https://github.com/elastic/elasticsearch/issues/121625

+ 2 - 2
server/src/main/java/org/elasticsearch/bootstrap/Elasticsearch.java

@@ -118,9 +118,9 @@ class Elasticsearch {
         final PrintStream out = getStdout();
         final PrintStream err = getStderr();
         final ServerArgs args;
-        final boolean entitlementsExplicitlyEnabled = Booleans.parseBoolean(System.getProperty("es.entitlements.enabled", "false"));
+        final boolean entitlementsEnabled = Booleans.parseBoolean(System.getProperty("es.entitlements.enabled", "true"));
         // java 24+ only supports entitlements, but it may be enabled on earlier versions explicitly
-        final boolean useEntitlements = RuntimeVersionFeature.isSecurityManagerAvailable() == false || entitlementsExplicitlyEnabled;
+        final boolean useEntitlements = RuntimeVersionFeature.isSecurityManagerAvailable() == false || entitlementsEnabled;
         try {
             initSecurityProperties();