Were you able to configure another profile to run the tests with the security manager?
It's not (yet) a Maven profile; For now I ran the TCK TestNG test suite programmatically via a custom launcher class which let me debug missing permissions etc. It should be possible to create a Maven profile from that which runs the TCK with a security manager. Some more fiddling will be required though as I need to refer to the JARs in the local Maven repo when specifying the "code bases" in the policy file. My current set-up is hard-wired.
This profile could be activated for the CI builds.
+1 That'd be great.
|