閱讀612 返回首頁    go 阿裏雲


Java沙箱__MapReduce_大數據計算服務-阿裏雲

MaxCompute MapReduce及UDF程序在分布式環境中運行時受到Java沙箱的限製(MapReduce作業的主程序則不受此限製),具體限製如下:

  • 不允許直接訪問本地文件,隻能通過 MaxCompute MapReduce/Graph提供的接口間接訪問: 讀取- -resources選項指定的資源,包括文件、Jar包和資源表等; 通過System.out和System.err輸出日誌信息,可以通過ODPS客戶端的 Log 命令查看日誌信息;
  • 不允許直接訪問分布式文件係統,隻能透過ODPS MapReduce/Graph訪問到表的記錄:
  • 不允許JNI調用限製;
  • 不允許創建Java線程,不允許起子進程執行Linux命令;
  • 不允許訪問網絡,包括獲取本地IP地址等等都會被禁止;
  • Java反射限製,”suppressAccessChecks”權限被禁止,無法setAccessible某個private的屬性或方法,以達到讀取private屬性或調用private方法的目的。

具體的說,在用戶代碼中直接使用下麵這些方法會拋”access denied”異常:

訪問本地文件相關方法

java.io.File:

  1. public boolean delete()
  2. public void deleteOnExit()
  3. public boolean exists()
  4. public boolean canRead()
  5. public boolean isFile()
  6. public boolean isDirectory()
  7. public boolean isHidden()
  8. public long lastModified()
  9. public long length()
  10. public String[] list()
  11. public String[] list(FilenameFilter filter)
  12. public File[] listFiles()
  13. public File[] listFiles(FilenameFilter filter)
  14. public File[] listFiles(FileFilter filter)
  15. public boolean canWrite()
  16. public boolean createNewFile()
  17. public static File createTempFile(String prefix, String suffix)
  18. public static File createTempFile(String prefix, String suffix,File directory)
  19. public boolean mkdir()
  20. public boolean mkdirs()
  21. public boolean renameTo(File dest)
  22. public boolean setLastModified(long time)
  23. public boolean setReadOnly()

java.io.RandomAccessFile:

  1. RandomAccessFile(String name, String mode)
  2. RandomAccessFile(File file, String mode)

java.io.FileInputStream:

  1. FileInputStream(FileDescriptor fdObj)
  2. FileInputStream(String name)
  3. FileInputStream(File file)

java.io.FileOutputStream:

  1. FileOutputStream(FileDescriptor fdObj)
  2. FileOutputStream(File file)
  3. FileOutputStream(String name)
  4. FileOutputStream(String name, boolean append)

java.lang.Class:

  1. public ProtectionDomain getProtectionDomain()

java.lang.ClassLoader:

  1. ClassLoader()
  2. ClassLoader(ClassLoader parent)

java.lang.Runtime:

  1. public Process exec(String command)
  2. public Process exec(String command, String envp[])
  3. public Process exec(String cmdarray[])
  4. public Process exec(String cmdarray[], String envp[])
  5. public void exit(int status)
  6. public static void runFinalizersOnExit(boolean value)
  7. public void addShutdownHook(Thread hook)
  8. public boolean removeShutdownHook(Thread hook)
  9. public void load(String lib)
  10. public void loadLibrary(String lib)

java.lang.System:

  1. public static void exit(int status)
  2. public static void runFinalizersOnExit(boolean value)
  3. public static void load(String filename)
  4. public static void loadLibrary( String libname)
  5. public static Properties getProperties()
  6. public static void setProperties(Properties props)
  7. public static String getProperty(String key) // 隻允許部分key可以訪問
  8. public static String getProperty(String key, String def) // 隻允許部分key可以訪問
  9. public static String setProperty(String key, String value)
  10. public static void setIn(InputStream in)
  11. public static void setOut(PrintStream out)
  12. public static void setErr(PrintStream err)
  13. public static synchronized void setSecurityManager(SecurityManager s)

System.getProperty允許的key列表如下:

  1. java.version
  2. java.vendor
  3. java.vendor.url
  4. java.class.version
  5. os.name
  6. os.version
  7. os.arch
  8. file.separator
  9. path.separator
  10. line.separator
  11. java.specification.version
  12. java.specification.vendor
  13. java.specification.name
  14. java.vm.specification.version
  15. java.vm.specification.vendor
  16. java.vm.specification.name
  17. java.vm.version
  18. java.vm.vendor
  19. java.vm.name
  20. file.encoding
  21. user.timezone

java.lang.Thread:

  1. Thread()
  2. Thread(Runnable target)
  3. Thread(String name)
  4. Thread(Runnable target, String name)
  5. Thread(ThreadGroup group, ...)
  6. public final void checkAccess()
  7. public void interrupt()
  8. public final void suspend()
  9. public final void resume()
  10. public final void setPriority (int newPriority)
  11. public final void setName(String name)
  12. public final void setDaemon(boolean on)
  13. public final void stop()
  14. public final synchronized void stop(Throwable obj)
  15. public static int enumerate(Thread tarray[])
  16. public void setContextClassLoader(ClassLoader cl)

java.lang.ThreadGroup:

  1. ThreadGroup(String name)
  2. ThreadGroup(ThreadGroup parent, String name)
  3. public final void checkAccess()
  4. public int enumerate(Thread list[])
  5. public int enumerate(Thread list[], boolean recurse)
  6. public int enumerate(ThreadGroup list[])
  7. public int enumerate(ThreadGroup list[], boolean recurse)
  8. public final ThreadGroup getParent()
  9. public final void setDaemon(boolean daemon)
  10. public final void setMaxPriority(int pri)
  11. public final void suspend()
  12. public final void resume()
  13. public final void destroy()
  14. public final void interrupt()
  15. public final void stop()

java.lang.reflect.AccessibleObject:

  1. public static void setAccessible(...)
  2. public void setAccessible(...)

java.net.InetAddress:

  1. public String getHostName()
  2. public static InetAddress[] getAllByName(String host)
  3. public static InetAddress getLocalHost()

java.net.DatagramSocket:

  1. public InetAddress getLocalAddress()

java.net.Socket:

  1. Socket(...)

java.net.ServerSocket:

  1. ServerSocket(...)
  2. public Socket accept()
  3. protected final void implAccept(Socket s)
  4. public static synchronized void setSocketFactory(...)
  5. public static synchronized void setSocketImplFactory(...)

java.net.DatagramSocket:

  1. DatagramSocket(...)
  2. public synchronized void receive(DatagramPacket p)

java.net.MulticastSocket:

  1. MulticastSocket(...)

java.net.URL:

  1. URL(...)
  2. public static synchronized void setURLStreamHandlerFactory(...)
  3. java.net.URLConnection
  4. public static synchronized void setContentHandlerFactory(...)
  5. public static void setFileNameMap(FileNameMap map)

java.net.HttpURLConnection:

  1. public static void setFollowRedirects(boolean set)
  2. java.net.URLClassLoader
  3. URLClassLoader(...)

java.security.AccessControlContext:

  1. public AccessControlContext(AccessControlContext acc, DomainCombiner combiner)
  2. public DomainCombiner getDomainCombiner()

最後更新:2016-06-22 13:00:14

  上一篇:go 本地運行__功能介紹_MapReduce_大數據計算服務-阿裏雲
  下一篇:go WordCount示例__示例程序_MapReduce_大數據計算服務-阿裏雲