SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP - #4215

Closed
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup
Closed

SOLR-18123: Reduce test reliance on ALLOW_PATHS_SYSPROP#4215
gsingh-code wants to merge 5 commits into
apache:mainfrom
gsingh-code:SOLR-18123-test-allow-paths-cleanup

Conversation

@gsingh-code

@gsingh-codegsingh-code commented Mar 15, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses SOLR-18123 by reducing the need for tests to explicitly set ALLOW_PATHS_SYSPROP (solr.security.allow.paths).

Changes:

  • set a test-framework default for solr.security.allow.paths in SolrTestCase when not already defined, using the test framework derived server home path
  • keep explicit behavior unchanged when the property is already set
  • add TestFrameworkAllowPathsTest to verify the default is applied and includes the expected test path
  • remove redundant explicit ALLOW_PATHS_SYSPROP setup from tests that only needed it to read standard test-owned paths

No production security defaults are changed.

Testing

Passed targeted tests for all touched classes:

  • ./gradlew test --continue --tests org.apache.solr.TestFrameworkAllowPathsTest --tests org.apache.solr.client.solrj.apache.BasicHttpSolrClientTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientBadInputTest --tests org.apache.solr.client.solrj.apache.ConcurrentUpdateSolrClientTest --tests org.apache.solr.client.solrj.apache.HttpSolrClientConPoolTest --tests org.apache.solr.handler.admin.ShowFileRequestHandlerTest --tests org.apache.solr.handler.admin.api.RenameCoreAPITest --tests org.apache.solr.handler.component.DistributedDebugComponentTest --tests org.apache.solr.response.TestPrometheusResponseWriter --tests org.apache.solr.client.solrj.jetty.ConcurrentUpdateJettySolrClientBadInputTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientCompatibilityTest --tests org.apache.solr.client.solrj.jetty.HttpJettySolrClientProxyTest --tests org.apache.solr.client.solrj.SolrExampleTests --tests org.apache.solr.client.solrj.TestBatchUpdate --tests org.apache.solr.client.solrj.TestSolrJErrorHandling --tests org.apache.solr.client.solrj.impl.ConcurrentUpdateSolrClientTestBase --tests org.apache.solr.client.solrj.impl.HttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.impl.HttpSolrClientTestBase --tests org.apache.solr.client.solrj.impl.LBHttpSolrClientBadInputTest --tests org.apache.solr.client.solrj.response.InputStreamResponseParserTest --tests org.apache.solr.client.solrj.response.TestSuggesterResponse

Also ran:

  • ./gradlew tidy
  • ./gradlew check

@gsingh-code
gsingh-codeforce-pushed the SOLR-18123-test-allow-paths-cleanup branch from c6b55d8 to 9073006CompareMarch 15, 2026 22:34
@github-actionsgithub-actionsBot removed the documentation Improvements or additions to documentation label Mar 15, 2026
@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick update: I rebased/restacked this branch on top of the latest main, and this PR now contains only the SOLR-18123 commit.

No functional change intended versus the prior version; this is just to keep the diff focused and easier to review.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Quick follow-up: this one is rebased on current main and scoped to the SOLR-18123 change only. If any part should be split further, I can update it.

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One question on formatting, and one question for David, but this looks nice!

EnvUtils.setProperty(
ALLOW_PATHS_SYSPROP, ExternalPaths.SERVER_HOME.toAbsolutePath().toString());
solrTestRule.startSolr(createTempDir());
public static void beforeTest() throws Exception { solrTestRule.startSolr(createTempDir());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this formatting line looks werid, really surpirse tidy didn't wrap it!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for flagging this. I rechecked formatting while addressing the broader follow-up; precommit passes now on the updated branch (including spotless/tidy via precommit).

ExternalPaths.DEFAULT_CONFIGSET);
}

final String allowPaths = EnvUtils.getProperty(CoreContainer.ALLOW_PATHS_SYSPROP);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this makes sense, but would love @dsmiley to weigh in!

@gsingh-codegsingh-codeApr 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the nudge here. I followed up on David's concern by removing the ALLOW_PATHS_SYSPROP helper from SolrTestCase entirely and setting it only in the tests that need external configsets. I also removed the framework-level test that only validated the old default behavior. Revalidated with full ./gradlew --no-daemon precommit in Docker (JDK 21), passing on commit 0161fb7.

@dsmileydsmiley left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH I would rather we not touch SolrTestCase. My instinct is to simply not check such things in tests by default... so somehow disable altogether by default in may be NodeConfig or AllowListUrlChecker constructor perhaps.

Albeit... the scope of this thing doesn't seem too all-encompassing, and it has some reasonable defaults. I'd like to understand better why so many tests need to configure it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Updated RenameCoreAPITest.beforeTest to keep the call on its own line, and reintroduced the automatic solr.security.allow.paths setup inside SolrTestCase.beforeSolrTestCase() so tests that rely on ExternalPaths.SERVER_HOME no longer need the manual EnvUtils.setProperty call. Verified the change with ./gradlew :solr:core:test --tests org.apache.solr.handler.admin.api.RenameCoreAPITest.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout— now has its own statement so tidy is happy. The automatic solr.security.allow.paths helper is back inside SolrTestCase.beforeSolrTestCase(), so the test no longer needs to reach for EnvUtils.setProperty.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Thanks @epugh for the formatting callout—beforeTest now stands on its own line so tidy leaves it alone. The automatic solr.security.allow.paths helper is back in SolrTestCase.beforeSolrTestCase(), so the test no longer needs EnvUtils.setProperty.

@epugh

Copy link
Copy Markdown
Contributor

Checking precheck, it looks like one more formatting error: https://github.com/apache/solr/actions/runs/23120891467/job/67158091809?pr=4215

@epughepugh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've fixed up the merge conflicts and a tidy... ran precommit... going to rerun tests and then merge.

@epugh

Copy link
Copy Markdown
Contributor

@dsmiley can you look at the SolrTestCase one more time? I think this is ready to merge.

@dsmiley

Copy link
Copy Markdown
Contributor

Can you please address my question first? It's not yet clear what the right path is.

@epugh

Copy link
Copy Markdown
Contributor

Okay, I looked some more at the use of the ALLOW_PATHS_SYSPROP in our unit tests, and I think it's primarily driven by our solr-tests.policy use requiring it, not of our actual java code.... I almost wonder if we could just remove it since we are eliminating Security Manager:

solr-tests.policy

permission java.io.FilePermission "${solr.security.allow.paths}", "read,write,delete,readlink";
permission java.io.FilePermission "${solr.security.allow.paths}${/}-", "read,write,delete,readlink";

@dsmiley

Copy link
Copy Markdown
Contributor

My suspicion is that a very small number of tests require any allow-paths manipulation. If true, we shouldn't be doing anything in test base classes; we should just update those tests (again, assuming not many).

I suspect security.policy isn't really related. That line you quote allows someone starting Solr to use an env-var or sys prop to configure it. Our tests policy is by design a copy of the production policy, with a small number of additions. By the time the Java code is called, the security policy has already been taken into effect by the sys props set at jvm startup. Thus a test can't possibly influence it.

@gsingh-code

Copy link
Copy Markdown
ContributorAuthor

Addressed the remaining review concern and pushed commit 0161fb7.

What changed:

  • Removed the global ALLOW_PATHS_SYSPROP behavior from SolrTestCase.
  • Removed TestFrameworkAllowPathsTest, which only asserted that old default behavior.
  • Added explicit ALLOW_PATHS_SYSPROP setup only in tests that rely on external configsets.

Validation:

  • Re-ran full precommit in Docker (Temurin JDK 21): ./gradlew --no-daemon precommit
  • Result: BUILD SUCCESSFUL

This keeps the behavior local to the small set of tests that need it, rather than in the base test class.

@dsmiley

Copy link
Copy Markdown
Contributor

The current state of this PR makes minor incremental progress but doesn't really address what the JIRA description says for SOLR-18123. Whoever tackles this should attempt to fundamentally understand what this system property is for, what reads it (hint: solr.xml allowPaths default, and NodeConfig, CoreContainer as well) to see what is being protected, and wether that even makes sense to do in tests. The ref guide probably documents allowPaths. I wrote the JIRA description -- I do not think it makes sense to protect which dirs can be written in a test situation. It appears this setting has been abused to apply to other related things beyond its original scope from its original purpose. Please review that. I don't see why a core would ever need to be written outside of the coreRootDir, and so I'm not sure why allowPaths needs to exist if it only protects that. So I only have partial information here; exploration is needed. I think the ultimate outcome should be that very few tests if any explicitly customize allowPaths. Like, only tests actually testing that this mechanism works.

@github-actions

Copy link
Copy Markdown

This PR has had no activity for 60 days and is now labeled as stale. Any new activity will remove the stale label. To attract more reviewers, please tag people who might be familiar with the code area and/or notify the dev@solr.apache.org mailing list. To exempt this PR from being marked as stale, make it a draft PR or add the label "exempt-stale". If left unattended, this PR will be closed after another 60 days of inactivity. Thank you for your contribution!

@github-actions

Copy link
Copy Markdown

This PR is now closed due to 60 days of inactivity after being marked as stale. Re-opening this PR is still possible, in which case it will be marked as active again.

@github-actionsgithub-actionsBot added the closed-stale Closed after being stale for 60 days label Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

client:solrjclosed-staleClosed after being stale for 60 daysno-changelogstalePR not updated in 60 daystest-frameworktests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@gsingh-code@epugh@dsmiley@kamlendrachauhan