| Product | Version |
| Spotfire Service for TERR / Spotfire Service for R / Spotfire Statistics Services | All Versions |
Keywords:
TERR, restricted execution mode, T-REX, terr.restricted.execution.mode, data function, trusted data function, restricted call, restricted call to Native, custom.properties, export-service-config, import-service-config, TERR Service, Spotfire Service for R, Spotfire Enterprise Runtime for R - Server Edition, Spotfire Statistics Services, Web Player, Automation Services
Introduction: This article explains when the TERR restricted execution mode error occurs and how to change the service configuration to resolve it. It applies to Spotfire Service for TERR and Spotfire Service for R.
Error Message:
The data function 'Data_Function_TERR' has been trusted, but it was executed in restricted execution mode.
Spotfire Statistics Services and/or the TERR service are configured to enforce restricted execution mode. This configuration must be changed or the data function must be rewritten to work in restricted mode.
Error: restricted call
When This Error Occurs:
- The data function works in the Spotfire desktop client but fails in Web Player or Automation Services. These run data functions on the TERR Service, Spotfire Service for R, or Spotfire Statistics Services.
- TERR Restricted Execution Mode (also called T-REX mode) is turned on by default (terr.restricted.execution.mode=true). It keeps the environment secure by letting only a limited set of low-risk functions run. If the data function uses a function that isn't allowed, it fails with this error.
- Trust decides how a data function runs. By design, the service always runs a data function that isn't trusted in restricted mode, whatever terr.restricted.execution.mode is set to.
Requirements to Run Outside Restricted Mode:
- The data function must be trusted.
- terr.restricted.execution.mode must be set to false in the service configuration, and the new configuration must be applied to the service.
- You need administrative read-write privileges on Spotfire Server to save the changed configuration.
How to Change the Configuration (TERR Service / Spotfire Service for R):
-
Open the Spotfire Server Command Line
- On the Spotfire Server computer, open a command prompt and go to <Spotfire Server installation folder>/tomcat/spotfire-bin.
-
Export the Service Configuration
- Run: config export-service-config --capability=TERR --deployment-area=<your deployment area>
- This exports the service configuration files, including custom.properties, to a config folder.
- Note: If you've already created a custom configuration, add --config-name=<name> to export it. If you don't give a name, the default configuration is exported.
-
Edit custom.properties
- Open the exported custom.properties file and set: terr.restricted.execution.mode=false
- Save the file.
-
Import the Service Configuration
- Run: config import-service-config --config-name=<new configuration name>
-
Apply the New Configuration
- In Spotfire Server, go to Administration > Nodes & Services, select the service instance, edit it, and select the new configuration. The service restarts with the new setting.
-
Make Sure the Data Function Is Trusted and Test
- Check that the data function is still trusted. Then run it again in Web Player or Automation Services.
-
Contact Revvity Signals Support
- If the error continues, contact Support. Include your Signals tenant URL, your Spotfire and service versions, the full error message, and the data function name.
Note: For Spotfire Statistics Services, the same setting is in custom.properties in the instance's conf folder. Restart Spotfire Statistics Services after you change it.
Documentation:
- Error: "Restricted call to Native[file]" on Spotfire TERR Service even if terr.restricted.execution.mode is set to false
- TERR error in Spotfire Web Player: "The data function 'Test' has been trusted, but it was executed in restricted execution mode"
- Spotfire Service for TERR: Configuring the Service
- Spotfire Service for TERR 1.21.2: Safeguarding your environment
- Spotfire Enterprise Runtime for R - Server Edition 1.17.4 Documentation
- Spotfire Enterprise Runtime for R - Server Edition 1.17.4: Safeguarding your environment
Critical Note: A data function runs outside restricted mode only when both are true: the data function is trusted, and terr.restricted.execution.mode=false is set in the service configuration (export, edit, import, then apply). Turning off restricted mode lowers security, so review Safeguarding your environment before you change it.
Comments
0 comments
Please sign in to leave a comment.