Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-30432

"Scripts not permitted to use method" in Jenkins Workflow

      Inlining the script https://github.com/arun-gupta/javaee7-docker-workflow/blob/master/Jenkinsfile in Jenkins workflow builds the project successfully. But referring as a SCM script gives the following error:

      First time build. Skipping changelog.
      Running: Allocate node : Start
      Running on master in /var/jenkins_home/jobs/hello2/workspace
      Running: Allocate node : Body : Start
      Running: Allocate node : Body : End
      Running: Allocate node : End
      Running: End of Workflow
      org.jenkinsci.plugins.scriptsecurity.sandbox.RejectedAccessException: Scripts not permitted to use method groovy.lang.GroovyObject invokeMethod java.lang.String java.lang.Object
      at org.jenkinsci.plugins.scriptsecurity.sandbox.whitelists.StaticWhitelist.rejectMethod(StaticWhitelist.java:150)
      at org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.SandboxInterceptor.onMethodCall(SandboxInterceptor.java:77)
      at org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.SandboxInterceptor.onMethodCall(SandboxInterceptor.java:60)
      at org.kohsuke.groovy.sandbox.impl.Checker$1.call(Checker.java:103)
      at org.kohsuke.groovy.sandbox.impl.Checker.checkedCall(Checker.java:100)
      at com.cloudbees.groovy.cps.sandbox.SandboxInvoker.methodCall(SandboxInvoker.java:15)
      at WorkflowScript.run(WorkflowScript:2)
      at Unknown.Unknown(Unknown)
      at __cps.transform__(Native Method)
      at com.cloudbees.groovy.cps.impl.ContinuationGroup.methodCall(ContinuationGroup.java:69)
      at com.cloudbees.groovy.cps.impl.FunctionCallBlock$ContinuationImpl.dispatchOrArg(FunctionCallBlock.java:106)
      at com.cloudbees.groovy.cps.impl.FunctionCallBlock$ContinuationImpl.fixArg(FunctionCallBlock.java:79)
      at sun.reflect.GeneratedMethodAccessor193.invoke(Unknown Source)
      at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
      at java.lang.reflect.Method.invoke(Method.java:497)
      at com.cloudbees.groovy.cps.impl.ContinuationPtr$ContinuationImpl.receive(ContinuationPtr.java:72)
      at com.cloudbees.groovy.cps.impl.ConstantBlock.eval(ConstantBlock.java:21)
      at com.cloudbees.groovy.cps.Next.step(Next.java:58)
      at com.cloudbees.groovy.cps.Continuable.run0(Continuable.java:145)
      at org.jenkinsci.plugins.workflow.cps.SandboxContinuable.access$001(SandboxContinuable.java:19)
      at org.jenkinsci.plugins.workflow.cps.SandboxContinuable$1.call(SandboxContinuable.java:33)
      at org.jenkinsci.plugins.workflow.cps.SandboxContinuable$1.call(SandboxContinuable.java:30)
      at org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.GroovySandbox.runInSandbox(GroovySandbox.java:106)
      at org.jenkinsci.plugins.workflow.cps.SandboxContinuable.run0(SandboxContinuable.java:30)
      at org.jenkinsci.plugins.workflow.cps.CpsThread.runNextChunk(CpsThread.java:164)
      at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup.run(CpsThreadGroup.java:271)
      at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup.access$000(CpsThreadGroup.java:71)
      at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup$2.call(CpsThreadGroup.java:180)
      at org.jenkinsci.plugins.workflow.cps.CpsThreadGroup$2.call(CpsThreadGroup.java:178)
      at org.jenkinsci.plugins.workflow.cps.CpsVmExecutorService$2.call(CpsVmExecutorService.java:47)
      at java.util.concurrent.FutureTask.run(FutureTask.java:266)
      at hudson.remoting.SingleLaneExecutorService$1.run(SingleLaneExecutorService.java:112)
      at jenkins.util.ContextResettingExecutorService$1.run(ContextResettingExecutorService.java:28)
      at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
      at java.util.concurrent.FutureTask.run(FutureTask.java:266)
      at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
      at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
      at java.lang.Thread.run(Thread.java:745)
      Finished: FAILURE

          [JENKINS-30432] "Scripts not permitted to use method" in Jenkins Workflow

          arungupta created issue -

          arungupta added a comment -

          Worked around by going to Manage Jenkins -> In-process Script Approval, and clicking on "Approve" button for invokeMethod.

          Weird, but worked!

          arungupta added a comment - Worked around by going to Manage Jenkins -> In-process Script Approval, and clicking on "Approve" button for invokeMethod. Weird, but worked!

          Jesse Glick added a comment -

          No, do not approve that. It would be security risk. Delete approvals. Something is wrong but there is not enough information here to diagnose what. No software versions even.

          Jesse Glick added a comment - No, do not approve that. It would be security risk. Delete approvals. Something is wrong but there is not enough information here to diagnose what. No software versions even.

          arungupta added a comment -

          Jenkins version: 1.609.2

          Workflow: https://github.com/arun-gupta/javaee7-docker-workflow/blob/master/Jenkinsfile

          What else is needed?

          arungupta added a comment - Jenkins version: 1.609.2 Workflow: https://github.com/arun-gupta/javaee7-docker-workflow/blob/master/Jenkinsfile What else is needed?

          Jesse Glick added a comment -

          Versions of at least the Workflow plugins and Script Security. If in doubt, install the Support Core plugin and attach a support bundle for diagnosis.

          Jesse Glick added a comment - Versions of at least the Workflow plugins and Script Security. If in doubt, install the Support Core plugin and attach a support bundle for diagnosis.
          Jesse Glick made changes -
          Resolution New: Incomplete [ 4 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]

          Jesse Glick added a comment -

          Did you perchance install the Build Flow plugin? Or the Analysis Collector plugin? (A support bundle would let me know without having to ask.)

          Jesse Glick added a comment - Did you perchance install the Build Flow plugin? Or the Analysis Collector plugin? (A support bundle would let me know without having to ask.)

          Jesse Glick added a comment -

          Will improve Script Security to warn you against this incorrect workaround.

          Jesse Glick added a comment - Will improve Script Security to warn you against this incorrect workaround.
          Jesse Glick made changes -
          Remote Link New: This issue links to "script-security PR 24 (Web Link)" [ 13150 ]

          arungupta added a comment -

          Workflow plugin is 1.10
          Script Security is 1.13

          Docker image is created using https://github.com/javaee-samples/docker-java/tree/master/attendees/cicd/jenkins

          Specifying complete list of plugins is quite painful anyway. I was hoping that it would resolve the dependencies but apparently not, related to: https://issues.jenkins-ci.org/browse/JENKINS-30361

          arungupta added a comment - Workflow plugin is 1.10 Script Security is 1.13 Docker image is created using https://github.com/javaee-samples/docker-java/tree/master/attendees/cicd/jenkins Specifying complete list of plugins is quite painful anyway. I was hoping that it would resolve the dependencies but apparently not, related to: https://issues.jenkins-ci.org/browse/JENKINS-30361

            jglick Jesse Glick
            arungupta arungupta
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: