Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-66927

com.thoughtworks.xstream.security.ForbiddenClassException thrown on call to xldDeploy after upgrade to Jenkins 2.303.2

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • None
    • Jenkins 2.303.2 with deployit-plugin 10.0.4
      Jenkins 2.303.3 with deployit-plugin 10.0.5

      After upgrating Jenkins to 2.303.2, I get the following error when calling the xldDeploy step :

      com.thoughtworks.xstream.security.ForbiddenClassException: com.xebialabs.deployit.engine.api.dto.Deployment
          at com.thoughtworks.xstream.security.NoTypePermission.allows(NoTypePermission.java:26)
          at com.thoughtworks.xstream.mapper.SecurityMapper.realClass(SecurityMapper.java:74)
          at com.thoughtworks.xstream.mapper.MapperWrapper.realClass(MapperWrapper.java:125)
          at com.thoughtworks.xstream.mapper.CachingMapper.realClass(CachingMapper.java:47)
          at com.thoughtworks.xstream.core.util.HierarchicalStreams.readClassType(HierarchicalStreams.java:29)
          at com.thoughtworks.xstream.core.TreeUnmarshaller.start(TreeUnmarshaller.java:133)
          at com.thoughtworks.xstream.core.AbstractTreeMarshallingStrategy.unmarshal(AbstractTreeMarshallingStrategy.java:32)
          at com.thoughtworks.xstream.XStream.unmarshal(XStream.java:1391)
          at com.xebialabs.xltype.serialization.xstream.XStreamReaderWriter.read(XStreamReaderWriter.java:149)
          at com.xebialabs.xltype.serialization.xstream.XStreamReaderWriter.readFrom(XStreamReaderWriter.java:143)
          at org.jboss.resteasy.core.interception.AbstractReaderInterceptorContext.readFrom(AbstractReaderInterceptorContext.java:61)
          at org.jboss.resteasy.core.interception.AbstractReaderInterceptorContext.proceed(AbstractReaderInterceptorContext.java:53)
          at org.jboss.resteasy.plugins.interceptors.encoding.GZIPDecodingInterceptor.aroundReadFrom(GZIPDecodingInterceptor.java:59)
          at org.jboss.resteasy.core.interception.AbstractReaderInterceptorContext.proceed(AbstractReaderInterceptorContext.java:55)
          at org.jboss.resteasy.client.core.BaseClientResponse.readFrom(BaseClientResponse.java:448)
      Caused: org.jboss.resteasy.spi.ReaderException
          at org.jboss.resteasy.client.core.BaseClientResponse.readFrom(BaseClientResponse.java:483)
          at org.jboss.resteasy.client.core.BaseClientResponse.getEntity(BaseClientResponse.java:396)
          at org.jboss.resteasy.client.core.BaseClientResponse.getEntity(BaseClientResponse.java:367)
          at org.jboss.resteasy.client.core.extractors.BodyEntityExtractor.extractEntity(BodyEntityExtractor.java:75)
          at com.xebialabs.deployit.booter.remote.resteasy.DeployitBodyEntityExtractor.extractEntity(DeployitBodyEntityExtractor.java:27)
          at org.jboss.resteasy.client.core.ClientInvoker.invoke(ClientInvoker.java:138)
          at org.jboss.resteasy.client.core.ClientProxy.invoke(ClientProxy.java:98)
          at com.sun.proxy.$Proxy156.prepareUpdate(Unknown Source)
          at com.xebialabs.deployit.ci.server.DeployCommand.deploy(DeployCommand.java:102)
          at com.xebialabs.deployit.ci.server.DeployitServerImpl.deploy(DeployitServerImpl.java:89)
          at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
          at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
          at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
          at java.lang.reflect.Method.invoke(Method.java:497)
          at com.xebialabs.deployit.ci.server.PluginFirstClassloaderInvocationHandler.doInvoke(PluginFirstClassloaderInvocationHandler.java:70)
          at com.xebialabs.deployit.ci.server.PluginFirstClassloaderInvocationHandler.invoke(PluginFirstClassloaderInvocationHandler.java:56)
      Caused: com.xebialabs.deployit.ci.DeployitPluginException
          at com.xebialabs.deployit.ci.server.PluginFirstClassloaderInvocationHandler.invoke(PluginFirstClassloaderInvocationHandler.java:60)
          at com.sun.proxy.$Proxy126.deploy(Unknown Source)
          at com.xebialabs.deployit.ci.workflow.XLDeployDeployStep$XLDeployPublishExecution.run(XLDeployDeployStep.java:101)
          at com.xebialabs.deployit.ci.workflow.XLDeployDeployStep$XLDeployPublishExecution.run(XLDeployDeployStep.java:77)
          at org.jenkinsci.plugins.workflow.steps.AbstractSynchronousNonBlockingStepExecution$1$1.call(AbstractSynchronousNonBlockingStepExecution.java:47)
          at hudson.security.ACL.impersonate2(ACL.java:449)
          at hudson.security.ACL.impersonate(ACL.java:461)
          at org.jenkinsci.plugins.workflow.steps.AbstractSynchronousNonBlockingStepExecution$1.run(AbstractSynchronousNonBlockingStepExecution.java:44)
          at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
          at java.util.concurrent.FutureTask.run(FutureTask.java:266)
          at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
          at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
          at java.lang.Thread.run(Thread.java:745)
      

      It works fine with Jenkins 2.303.1

      Jenkins 2.303.2 upgraded XStream 1.4.17 to 1.4.18 (PR#5685)

          [JENKINS-66927] com.thoughtworks.xstream.security.ForbiddenClassException thrown on call to xldDeploy after upgrade to Jenkins 2.303.2

          Nicolas Gourdon created issue -
          Nicolas Gourdon made changes -
          Priority Original: Blocker [ 1 ] New: Major [ 3 ]
          Basil Crow made changes -
          Remote Link New: This issue links to "jenkinsci/xldeploy-plugin#83 (Web Link)" [ 27224 ]
          Basil Crow made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Basil Crow made changes -
          Status Original: In Progress [ 3 ] New: In Review [ 10005 ]
          Basil Crow made changes -
          Assignee Original: Wai Lee [ wlee1668 ] New: Surendar Suyamprakasam [ surendarsuyamprakasam ]
          Hilbert Schraal made changes -
          Environment Original: Jenkins 2.303.2
          deployit-plugin 10.0.4
          New: Jenkins 2.303.2 with deployit-plugin 10.0.4
          Jenkins 2.303.3 with deployit-plugin 10.0.5
          Surendar Suyamprakasam made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: In Review [ 10005 ] New: Resolved [ 5 ]
          Dirk Hamborg made changes -
          Resolution Original: Fixed [ 1 ]
          Status Original: Resolved [ 5 ] New: Reopened [ 4 ]
          Dirk Hamborg made changes -
          Comment [ With the new Version 10.0.6 appears this error

          ERROR: Build step failed with exception
          java.lang.ClassCastException: class java.security.MessageDigest$Delegate cannot be cast to class scala.Function0 (java.security.MessageDigest$Delegate is in module java.base of loader 'bootstrap'; scala.Function0 is in unnamed module of loader hudson.PluginFirstClassLoader @353d5b5f)
           at com.xebialabs.deployit.ci.dar.RemotePackaging.call(RemotePackaging.java:94)
           at com.xebialabs.deployit.ci.dar.RemotePackaging.call(RemotePackaging.java:51)
           at hudson.remoting.LocalChannel.call(LocalChannel.java:46)
           at com.xebialabs.deployit.ci.DeployitPerformer.doPerform(DeployitPerformer.java:76)
           at com.xebialabs.deployit.ci.DeployitNotifier.perform(DeployitNotifier.java:134)
           at hudson.tasks.BuildStepMonitor$3.perform(BuildStepMonitor.java:47)
           at hudson.model.AbstractBuild$AbstractBuildExecution.perform(AbstractBuild.java:814)
           at hudson.model.AbstractBuild$AbstractBuildExecution.performAllBuildSteps(AbstractBuild.java:763)
           at hudson.model.Build$BuildExecution.post2(Build.java:179)
           at hudson.model.AbstractBuild$AbstractBuildExecution.post(AbstractBuild.java:707)
           at hudson.model.Run.execute(Run.java:1921)
           at hudson.model.FreeStyleBuild.run(FreeStyleBuild.java:44)
           at hudson.model.ResourceController.execute(ResourceController.java:101)
           at hudson.model.Executor.run(Executor.java:442)
          Build step 'Deploy with XL Deploy' marked build as failure ]
          Surendar Suyamprakasam made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: Reopened [ 4 ] New: Fixed but Unreleased [ 10203 ]

            surendarsuyamprakasam Surendar Suyamprakasam
            ngourdon Nicolas Gourdon
            Votes:
            4 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: