[JIRA] (JENKINS-39654) HP_RUN_ID not available after Jenkins security change

4 views
Skip to first unread message

john.e.gregg@wellsfargo.com (JIRA)

unread,
Nov 10, 2016, 2:09:02 PM11/10/16
to jenkinsc...@googlegroups.com
John Gregg created an issue
 
Jenkins / Bug JENKINS-39654
HP_RUN_ID not available after Jenkins security change
Issue Type: Bug Bug
Assignee: Ofir Shaked
Components: hp-application-automation-tools-plugin
Created: 2016/Nov/10 7:08 PM
Priority: Blocker Blocker
Reporter: John Gregg

https://jenkins.io/blog/2016/05/11/security-update/

This security update prevents me from accessing HP_RUN_ID after the build has executed.

thanks

Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v7.1.7#71011-sha1:2526d7c)
Atlassian logo

kazak@hpe.com (JIRA)

unread,
Dec 12, 2016, 4:04:02 AM12/12/16
to jenkinsc...@googlegroups.com
Yafim Kazak commented on Bug JENKINS-39654
 
Re: HP_RUN_ID not available after Jenkins security change

Can you please supply more information?
Which prudoct is involved? which Step was used?
Please upload log and build config.
Which jenkins version you used? which OS?

john.e.gregg@wellsfargo.com (JIRA)

unread,
Dec 12, 2016, 12:59:02 PM12/12/16
to jenkinsc...@googlegroups.com

I only have experience with performance tests. I use the build step "Execute HP tests using Performance Center." The plugin tries to set an environment variable called HP_RUN_ID in PcBuilder.java. That parameter is no longer visible once the plugin completes its work because of the security restriction in the link I provided unless we follow the workarounds. I'm hoping you can do something to make this work again without needing a workaround. See the link for information.

I personally pass the HP_RUN_ID to Ant scripts to do various things.

The attached file jenkins-bad.txt shows the results of running a test, followed by a post-build step to execute a Windows batch command. In this case I'm just echoing %HP_RUN_ID%, which you can see is empty. I no longer have an installed old copy of Jenkins to test the previous behavior, but jenkins-good.txt shows what happens when I use one of the workarounds in the security note.

Thanks

john.e.gregg@wellsfargo.com (JIRA)

unread,
Dec 12, 2016, 12:59:02 PM12/12/16
to jenkinsc...@googlegroups.com
John Gregg updated an issue
 
Change By: John Gregg
Attachment: jenkins-good.txt

john.e.gregg@wellsfargo.com (JIRA)

unread,
Dec 12, 2016, 12:59:02 PM12/12/16
to jenkinsc...@googlegroups.com
John Gregg updated an issue
Change By: John Gregg
Attachment: jenkins-bad.txt

kazak@hpe.com (JIRA)

unread,
Dec 13, 2016, 6:01:01 AM12/13/16
to jenkinsc...@googlegroups.com
Yafim Kazak assigned an issue to Hanan Bem
Change By: Yafim Kazak
Assignee: Ofir Shaked Hanan Bem

oren.pelzman@hp.com (JIRA)

unread,
Dec 15, 2016, 3:19:01 AM12/15/16
to jenkinsc...@googlegroups.com
Oren Pelzman commented on Bug JENKINS-39654
 
Re: HP_RUN_ID not available after Jenkins security change

An internal defect has been submitted, we will address this in one of the upcoming releases.

kazak@hpe.com (JIRA)

unread,
Jan 2, 2017, 1:19:04 PM1/2/17
to jenkinsc...@googlegroups.com

hanan.bem@hpe.com (JIRA)

unread,
Jan 25, 2017, 6:49:04 AM1/25/17
to jenkinsc...@googlegroups.com
Hanan Bem updated an issue
Change By: Hanan Bem
https://jenkins.io/blog/2016/05/11/security-update/

This security update prevents me from accessing HP_RUN_ID after the build has executed.

thanks


As a temporary workaround please set the following argument to your Jenkins server (to your jenkins.xml for example):
-Dhudson.model.ParametersAction.safeParameters=HP_RUN_ID
As being described on the security update:
https://jenkins.io/blog/2016/05/11/security-update/
Thanks.

hanan.bem@hpe.com (JIRA)

unread,
Jan 25, 2017, 6:49:05 AM1/25/17
to jenkinsc...@googlegroups.com

As a temporary workaround please set the following argument to your Jenkins server (to your jenkins.xml for example):
-Dhudson.model.ParametersAction.safeParameters=HP_RUN_ID
As being described on the security update:
https://jenkins.io/blog/2016/05/11/security-update/

Thanks,
Hanan.

hanan.bem@hpe.com (JIRA)

unread,
Jan 29, 2017, 4:41:02 AM1/29/17
to jenkinsc...@googlegroups.com
Hanan Bem updated an issue
Change By: Hanan Bem
Priority: Blocker Critical

hanan.bem@hpe.com (JIRA)

unread,
Jan 29, 2017, 6:44:02 AM1/29/17
to jenkinsc...@googlegroups.com
Hanan Bem started work on Bug JENKINS-39654
 
Change By: Hanan Bem
Status: Open In Progress

john.e.gregg@wellsfargo.com (JIRA)

unread,
Jul 24, 2019, 2:55:03 PM7/24/19
to jenkinsc...@googlegroups.com
John Gregg commented on Bug JENKINS-39654
 
Re: HP_RUN_ID not available after Jenkins security change

I'm using 5.6.2 and still see the same behavior.  I don't see anything in the committed files that looks like it addresses this problem.

This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)
Reply all
Reply to author
Forward
0 new messages