Inspect Declarative Permissions in a Mono Assembly with permview
You will finish with a repeatable way to inspect the declarative security permission sets embedded in a .NET assembly, optionally include class and method attributes, and save the result for comparison. This guide uses Mono permview 6.8.0.105 from Debian package mono-devel version 6.8.0.105+dfsg-3.6ubuntu2.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell, an assembly file that you are allowed to read, and the Mono development tools. The examples are read-only except for the report-file example. No command here needs sudo. The output describes declarative metadata; it does not grant permissions, alter an assembly, or change the runtime security policy.
1. Check the installed command
Start by confirming which binary will run and which package supplied it. These are ordinary read-only checks:
$ command -v permview
/usr/bin/permview
$ dpkg-query -W -f='${Package} ${Version}\n' mono-devel
mono-devel 6.8.0.105+dfsg-3.6ubuntu2
$ permview
Mono PermView - version 6.8.0.105
Managed Permission Viewer for .NET assemblies
...
Usage: permview [options] assembly
The final command deliberately omits its assembly. Its useful result is the usage text, which confirms the required shape: options come before one assembly path. A missing or unreadable assembly produces an error rather than a useful report.
Checkpoint
You should have an absolute path to permview, a package version, and a readable assembly to inspect. Do not use a path copied from a different host without checking that the file exists here.
2. Inspect assembly-level permission sets
Run permview with only the assembly path for the default report. On this machine, the framework assembly gives a compact example:
$ permview /usr/lib/mono/4.5/mscorlib.dll
Mono PermView - version 6.8.0.105
Managed Permission Viewer for .NET assemblies
...
Minimal Permission Set:
<PermissionSet class="System.Security.PermissionSet"
version="1">
<IPermission class="System.Security.Permissions.SecurityPermission, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"
version="1"
Flags="SkipVerification"/>
</PermissionSet>
Optional Permission Set:
Not specified.
Refused Permission Set:
Not specified.
Without -decl, the command reports the assembly-level minimum, optional, and refused permission sets. Treat Not specified. as an observation about that assembly, not as proof that every type or method has no security-related declaration.
These are metadata reports. A permission set shown here is not a command to enable access, and a missing set is not a diagnosis by itself. Use the report alongside the runtime error and the assembly's deployment context.
3. Include class and method declarations
Add -decl when the problem may be attached to a type or method rather than only to the assembly. The output can be much longer:
$ permview -decl /usr/lib/mono/4.5/mscorlib.dll | head -25
Mono PermView - version 6.8.0.105
Managed Permission Viewer for .NET assemblies
...
Assembly RequestMinimum Permission Set:
<PermissionSet class="System.Security.PermissionSet"
version="1">
...
Class Microsoft.Win32.SafeHandles.SafeHandleZeroOrMinusOneIsInvalid RequestMinimum Permission Set:
...
The head in this example only limits what is displayed on screen. It does not change what permview generates. Remove it when you need the complete report, or redirect the command to a file as shown next.
Checkpoint
Use the default mode first for a quick assembly-level view. Use -decl for a full investigation, especially when a particular class or method throws a SecurityException.
4. Produce XML, and test the actual assembly
The -xml option asks for XML output. Choose an assembly that is known to produce valid output and inspect the first lines:
$ permview -xml /usr/lib/mono/2.0-api/Accessibility.dll | head -15
Mono PermView - version 6.8.0.105
Managed Permission Viewer for .NET assemblies
...
<Assembly Name="Accessibility, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a">
<Actions>
<Action Name="RequestMinimum">
...
Do not assume that every assembly will succeed in XML mode. With this Mono 6.8.0.105 build, permview -xml /usr/lib/mono/4.5/mscorlib.dll fails with an Invalid XML attribute value exception while processing one of mscorlib's attributes. That is a tool or input compatibility failure, not evidence that the assembly is corrupt. Retry without -xml, try a smaller assembly, and keep the error in your investigation record.
The manpage lists several help spellings, while this installed binary's usage text presents -help. For a reliable local syntax check, run permview with no assembly and read the usage it prints. Do not infer support for an option merely because another Mono release documents it.
5. Save a report without losing an existing file
-output filename writes the report to the named file instead of leaving the report body on standard output. The command will create or overwrite that path, so treat an existing report as valuable before running it. The following uses a deliberately new path under /tmp:
$ report=/tmp/permview-mscorlib.txt
$ test ! -e "$report" || { printf 'Refusing to overwrite %s\n' "$report" >&2; exit 1; }
$ permview -output "$report" /usr/lib/mono/4.5/mscorlib.dll
$ printf 'report: %s\n' "$report"
report: /tmp/permview-mscorlib.txt
$ sed -n '1,14p' "$report"
Minimal Permission Set:
<PermissionSet class="System.Security.PermissionSet"
version="1">
...
There is no persistent configuration to undo. If the report is no longer needed, remove only the exact temporary file after checking its path:
$ test "$report" = /tmp/permview-mscorlib.txt && rm -- "$report"
If you need an audit trail, store the report in an approved directory with suitable permissions instead of a shared temporary directory. The report may reveal assembly structure and security metadata, so handle it according to your local policy.
6. Interpret failures safely
A FileNotFoundException normally means the assembly path is wrong, not that elevated privileges are required. Check the path without changing anything:
$ test -r /path/to/application.dll && printf 'readable\n' || printf 'missing or unreadable\n'
$ permview /path/to/application.dll
For an unreadable file, ask its owner or administrator for an approved copy or read access. Do not loosen permissions on a production assembly merely to make an inspection command work. A non-zero result from XML mode, a damaged file, or a runtime-specific metadata feature should be recorded with the exact Mono version and assembly path.
Done means
- You confirmed the installed
permviewbinary and Mono package version. - You inspected assembly-level permission sets without changing the assembly.
- You know that
-decladds class and method declarations and can greatly expand output. - You tested XML output against the actual assembly and recognised the mscorlib failure on this Mono build.
- You saved a report only after checking that the destination would not be overwritten accidentally.
- You kept permission metadata separate from granting access or changing runtime policy.